PowerShell Remoting Lateral Movement via WSMan/WinRM Sessions

This rule detects potentially malicious PowerShell command execution originating from a Windows Remote Management (WinRM) process (wsmprovhost.exe). It monitors for child processes of wsmprovhost.exe launching powershell.exe or pwsh.exe combined with indicators of obfuscated command-line arguments, such as encoded commands, base64 strings, or common bypass/evasion parameters like IEX or -NoProfile.