Skip to content
WinRM

WinRM Event ID 91: WSMan shell created (server)

Creating WSMan shell on serverWinRM event 91 is logged on the target when a remote WSMan shell is created, with the resource URI showing whether it is PowerShell remoting or winrs.
91
Event ID
91
Channel
Microsoft-Windows-WinRM/Operational
Provider
Microsoft-Windows-WinRM
Log file
Microsoft-Windows-WinRM%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 91 means

Event 91 is written by the WinRM service on the machine that receives a remote shell request. Its field resourceUri identifies the kind of shell: http://schemas.microsoft.com/powershell/Microsoft.PowerShell (or another session configuration) for PowerShell remoting, http://schemas.microsoft.com/wbem/wsman/1/windows/shell/cmd for winrs.

It is the target-side counterpart of event 6. Around the same timestamp expect a network logon (Security 4624 type 3), a wsmprovhost.exe process for PowerShell remoting or winrshost.exe for winrs, and PowerShell script block logging (4104) of the commands run in the session.

The event does not carry the source IP; get it from the logon event or from network telemetry.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-WinRM/Operational channel is enabled by default. The WinRM service must be running and listening, which is the default on Windows Server but not on client editions.

Key fields

FieldWhat it tells you
resourceUriResource URI of the shell requested by the client.
ValueMeaning
http://schemas.microsoft.com/powershell/Microsoft.PowerShellDefault PowerShell remoting endpoint (Enter-PSSession, Invoke-Command).
http://schemas.microsoft.com/wbem/wsman/1/windows/shell/cmdRemote command shell (winrs).

Common benign sources

  • Administrators and automation (configuration management, deployment tools) running remote PowerShell.
  • Monitoring and management products that connect over WinRM.

What attackers do that produces it

  • Incoming lateral movement through PowerShell remoting or winrs with valid or stolen credentials.
  • Remote command execution by offensive tools that implement WinRM.

Investigation tips

  • Correlate with Security 4624 (type 3) at the same time for the account and source IP.
  • Find wsmprovhost.exe / winrshost.exe in Security 4688 or Sysmon 1 and review their child processes.
  • Read PowerShell 4104 on the target for the commands executed in the session.
  • On the suspected source host, look for WinRM event 6 naming this machine.

MITRE ATT&CK techniques

TechniqueTactics
T1021.006 Remote Services: Windows Remote ManagementLateral Movement
T1059.001 Command and Scripting Interpreter: PowerShellExecution

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading