T1021.006 — Windows Remote Management
T1021.006: Windows Remote Management
MITRE ATT&CK® Enterprise technique
| Tactics | Lateral Movement |
| Platforms | Windows |
| Permissions required | — |
| Version | 1.2 |
| Parent technique | T1021 |
Description
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user.
WinRM is the name of both a Windows service and a protocol that allows a user to interact with a remote system (e.g., run an executable, modify the Registry, modify services).(Citation: Microsoft WinRM) It may be called with the winrm command or by any number of programs such as PowerShell.(Citation: Jacobsen 2014) WinRM can be used as a method of remotely interacting with Windows Management Instrumentation.(Citation: MSDN WMI)
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1021/006
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/