Skip to content
WinRM

WinRM Event ID 6: WSMan session created (client)

Creating WSMan SessionWinRM event 6 is logged on the client when a WS-Management session is created, with the connection string naming the remote host. Source-side PS remoting.
6
Event ID
6
Channel
Microsoft-Windows-WinRM/Operational
Provider
Microsoft-Windows-WinRM
Log file
Microsoft-Windows-WinRM%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 6 means

Event 6 is written by the WinRM client stack on the machine that initiates a WS-Management connection: Enter-PSSession, Invoke-Command, New-PSSession, winrs, CIM sessions over WSMan and management consoles. Its single field, connection, holds the connection string, which names the target host (and often the /wsman endpoint and client parameters).

That makes 6 one of the few source-side records of lateral movement over WinRM. On the target, the matching evidence is event 91 (shell created) in the same channel, a type 3 logon (Security 4624) and a wsmprovhost.exe or winrshost.exe process.

Connections to localhost are common: Server Manager, local PowerShell sessions and some management tools use WinRM against the local machine.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-WinRM/Operational channel is enabled by default.

The event is written on the client side only. Failed operations and authentication problems appear as other events in the same channel (for example 142 and 161).

Key fields

FieldWhat it tells you
connectionConnection string of the session — the remote host name or address, usually followed by the /wsman endpoint and client parameters. Unusual targets, raw IPs and servers the user never manages are the ones to check.

Common benign sources

  • Administrators using PowerShell remoting or winrs to manage servers.
  • Server Manager, System Center, monitoring tools and scripts using WinRM, including against localhost.

What attackers do that produces it

  • Lateral movement with PowerShell remoting (Invoke-Command, Enter-PSSession) or winrs from a compromised host.
  • Offensive tools that use WinRM for remote command execution with stolen credentials.

Investigation tips

  • List the targets in connection per source host and user; new pairs or many targets in a short time stand out.
  • On each target, look for WinRM 91, Security 4624 type 3 and wsmprovhost.exe / winrshost.exe process creation at the same time.
  • On the source, check PowerShell 4103/4104 for the commands that were sent.

MITRE ATT&CK techniques

TechniqueTactics
T1021.006 Remote Services: Windows Remote ManagementLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading