Evil-WinRM/WinRM-fs delivery of Bird Agent backdoor via WinRM

This rule monitors for execution patterns associated with the Evil-WinRM tool, a common post-exploitation framework used for remote command execution via WinRM. It identifies suspicious command-line arguments in PowerShell, the creation of configuration files typical of the tool, and network connections to WinRM ports initiated by common execution binaries like PowerShell or Ruby.