WinRM Lateral Movement via HTTP SOAP /wsman with PowerShell Commands
This rule detects potentially malicious activity leveraging the Windows Remote Management (WinRM) protocol over HTTP (ports 5985/5986). It specifically monitors for POST requests to the '/wsman' URI that contain the string 'powershell' in the request body, which is indicative of remote command execution via WinRM using PowerShell.
Suricata

