0f17ad6839
* [New Rule] Incoming Execution with WinRM Remote Shell * MITRE TID Mapping removed also unnecessary sequence events * Update lateral_movement_incoming_winrm_shell_execution.toml * eql syntax * ecs_version * excluding localhost * Update rules/windows/lateral_movement_incoming_winrm_shell_execution.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/windows/lateral_movement_incoming_winrm_shell_execution.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/windows/lateral_movement_incoming_winrm_shell_execution.toml Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> * Update rules/windows/lateral_movement_incoming_winrm_shell_execution.toml Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com> Co-authored-by: Brent Murphy <56412096+bm11100@users.noreply.github.com> Co-authored-by: Justin Ibarra <brokensound77@users.noreply.github.com>