According to ATT&CK, PowerShell can be used over WinRM to remotely run commands on a host. When a remote PowerShell session starts, svchost.exe executes wsmprovhost.exe
process = search Process:Create
wsmprovhost = filter process where (exe == "wsmprovhost.exe" and parent_exe == "svchost.exe")
For this to work, certain registry keys must be set, and the WinRM service must be enabled. The PowerShell command
Enter-PSSession -ComputerName \<RemoteHost\> creates a remote PowerShell session.
Data Model References