name: WinRM Spawning a Process id: a081836a-ba4d-11eb-8593-acde48001122 version: 1 date: '2021-05-21' author: Drew Church, Michael Haag, Splunk status: experimental type: TTP description: The following analytic identifies suspicious processes spawning from WinRM (wsmprovhost.exe). This analytic is related to potential exploitation of CVE-2021-31166. which is a kernel-mode device driver http.sys vulnerability. Current proof of concept code will blue-screen the operating system. However, http.sys used by many different Windows processes, including WinRM. In this case, identifying suspicious process create (child processes) from `wsmprovhost.exe` is what this analytic is identifying. data_source: - Sysmon Event ID 1 search: selection1: Image|endswith: - cmd.exe - sh.exe - bash.exe - powershell.exe - pwsh.exe - schtasks.exe - certutil.exe - whoami.exe - bitsadmin.exe - scp.exe ParentImage: wsmprovhost.exe condition: selection1 how_to_implement: To successfully implement this search you need to be ingesting information on process that include the name of the process responsible for the changes from your endpoints into the `Endpoint` datamodel in the `Processes` node. known_false_positives: Unknown. Add new processes or filter as needed. It is possible system management software may spawn processes from `wsmprovhost.exe`. references: - https://github.com/SigmaHQ/sigma/blob/9b7fb0c0f3af2e53ed483e29e0d0f88ccf1c08ca/rules/windows/process_access/win_susp_shell_spawn_from_winrm.yml - https://www.zerodayinitiative.com/blog/2021/5/17/cve-2021-31166-a-wormable-code-execution-bug-in-httpsys - https://github.com/0vercl0k/CVE-2021-31166/blob/main/cve-2021-31166.py tags: analytic_story: - Unusual Processes asset_type: Endpoint confidence: 50 cve: - CVE-2021-31166 impact: 50 message: tbd mitre_attack_id: - T1190 observable: - name: user type: User role: - Victim - name: dest type: Hostname role: - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud risk_score: 25 security_domain: endpoint