• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    WinRM Lateral Movement - Remote PowerShell or WMI SOAP Action on 5985/5986

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ankit Mehta@Secvyn
    •updated Jun 30, 2026•0•0•3

    Detects suspicious WinRM SOAPAction headers indicating potential lateral movement or remote command execution (e.g., shell command, process creation, or WMI operations) over WinRM HTTP ports 5985 and 5986.

    Suricata

    Tags

    T1021.006 - Windows Remote ManagementT1047 - Windows Management InstrumentationT1059.001 - PowerShellTA0008 - Lateral MovementTA0002 - ExecutionNetwork Connection InboundIDS IPS AlertCommand ExecutionRemote Access SessionWindowsSuricata IDSSnort IDSWindows Wmi ServiceHTTPTrojan Activity

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?