According to ATT&CK, PowerShell can be used over WinRM to remotely run commands on a host. When a remote PowerShell session starts, svchost.exe executes wsmprovhost.exe

ATT&CK Detection

Technique Tactic Level of Coverage
PowerShell Execution Moderate
Windows Remote Management Lateral Movement Moderate


process = search Process:Create
wsmprovhost = filter process where (exe == "wsmprovhost.exe" and parent_exe == "svchost.exe")

Additional Notes:

For this to work, certain registry keys must be set, and the WinRM service must be enabled. The PowerShell command Enter-PSSession -ComputerName \<RemoteHost\> creates a remote PowerShell session.

Data Model References

Object Action Field
process create exe
process create parent_exe