Umbra Wiki technique technique/T1021.006
Back to wiki

T1021.006 — Windows Remote Management

provenance: imported · ATT&CK: T1021.006

T1021.006: Windows Remote Management

MITRE ATT&CK® Enterprise technique

Tactics Lateral Movement
Platforms Windows
Permissions required
Version 1.2
Parent technique T1021

Description

Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.

WinRM is the name of both a Windows service and a protocol that allows a user to interact with a remote system (e.g., run an executable, modify the Registry, modify services).(Citation: Microsoft WinRM) It may be called with the winrm command or by any number of programs such as PowerShell.(Citation: Jacobsen 2014) WinRM can be used as a method of remotely interacting with Windows Management Instrumentation.(Citation: MSDN WMI)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1021/006
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/