Ransomware Series: WMI/WinRM Remote Execution for Lateral Movement

This rule detects potential lateral movement by identifying processes spawned via WMI (e.g., wmic.exe, WmiPrvSE.exe) or PowerShell Remoting (WinRM, Invoke-Command, Enter-PSSession) that occur shortly after a successful network or remote interactive logon on the same host.