MITRE ATT&CK

PowerShell remoting is a Windows feature that uses WinRM to allow remote command execution over an encrypted channel. It's widely used by system administrators for legitimate remote management, but attackers abuse it for lateral movement by executing malicious commands on target systems.


How Attackers Use It


Detection

Important Windows Event Logs

Important Sysmon Event IDs


Threat Hunting