Evil-WinRM/WinRM-fs Backdoor Delivery via WinRM (Toy Ghouls)
This rule monitors for suspicious activity originating from the WinRM service host (wsmprovhost.exe). It detects when command shells (cmd.exe, powershell.exe) are spawned by WinRM with known malicious command-line arguments (e.g., Evil-WinRM tools), monitors for the creation of potentially malicious configuration files (e.g., config.toml), and identifies established network connections to common WinRM ports (5985/5986) to detect unauthorized remote sessions.
Cortex XDR

