Ransomware Series: WMI/WinRM Remote Execution for Lateral Movement
This rule detects potential lateral movement by identifying processes spawned via WMI (e.g., wmic.exe, WmiPrvSE.exe) or PowerShell Remoting (WinRM, Invoke-Command, Enter-PSSession) that occur shortly after a successful network or remote interactive logon on the same host.
Microsoft Sentinel (KQL)

