Source host
Execution history (Prefetch)
WinRM execution history (Microsoft-Windows-WinRM/Operational)
Destination Host
Execution history (audit policy, Sysmon)
Communication via 5985/tcp (audit policy, Sysmon)
Source host/destination host: Event log "Application and Service\Microsoft\Windows\Windows Remote Management\Operational"
Last updated 2 years ago