Evil-WinRM/WinRM-fs delivery of Bird Agent backdoor via WinRM
This rule monitors for execution patterns associated with the Evil-WinRM tool, a common post-exploitation framework used for remote command execution via WinRM. It identifies suspicious command-line arguments in PowerShell, the creation of configuration files typical of the tool, and network connections to WinRM ports initiated by common execution binaries like PowerShell or Ruby.
Microsoft Sentinel (KQL)

