WinRM Event ID 91: WSMan shell created (server)
- Event ID
- 91
- Channel
- Microsoft-Windows-WinRM/Operational
- Provider
- Microsoft-Windows-WinRM
- Log file
- Microsoft-Windows-WinRM%4Operational.evtx
- Category
- Remote access
- Default logging
- Logged by default
What event 91 means
Event 91 is written by the WinRM service on the machine that receives a remote shell request. Its field resourceUri identifies the kind of shell: http://schemas.microsoft.com/powershell/Microsoft.PowerShell (or another session configuration) for PowerShell remoting, http://schemas.microsoft.com/wbem/wsman/1/windows/shell/cmd for winrs.
It is the target-side counterpart of event 6. Around the same timestamp expect a network logon (Security 4624 type 3), a wsmprovhost.exe process for PowerShell remoting or winrshost.exe for winrs, and PowerShell script block logging (4104) of the commands run in the session.
The event does not carry the source IP; get it from the logon event or from network telemetry.
When it is logged
None — the Microsoft-Windows-WinRM/Operational channel is enabled by default. The WinRM service must be running and listening, which is the default on Windows Server but not on client editions.
Key fields
| Field | What it tells you | ||||||
|---|---|---|---|---|---|---|---|
| resourceUri | Resource URI of the shell requested by the client.
|
Common benign sources
- Administrators and automation (configuration management, deployment tools) running remote PowerShell.
- Monitoring and management products that connect over WinRM.
What attackers do that produces it
- Incoming lateral movement through PowerShell remoting or
winrswith valid or stolen credentials. - Remote command execution by offensive tools that implement WinRM.
Investigation tips
- Correlate with Security 4624 (type 3) at the same time for the account and source IP.
- Find
wsmprovhost.exe/winrshost.exein Security 4688 or Sysmon 1 and review their child processes. - Read PowerShell 4104 on the target for the commands executed in the session.
- On the suspected source host, look for WinRM event 6 naming this machine.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.