V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
← Back to List
T1021.006EnterpriseSub-technique
Matrix: Enterprise
Status: Active
STIX: 19.0
Source ↗

Windows Remote Management

Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM). The adversary may then perform actions as the logged-on user. WinRM is the name of both a Windows service and a protocol that allows a user to interact with a remote system (e.g., run an executable, modify the Registry, modify services). It may be called with the `winrm` command or by any number of programs such as PowerShell. WinRM can be used as a method of remotely interacting with Windows Management Instrumentation.

Tactics

Lateral Movement

Parent technique

T1021
Remote Services

Platforms

Windows
Open in catalog with ATT&CK filter →

Related CAPECs

Affected vulnerabilities (Inferred)

No matches — refine the filter to see a result.