Port 5986: Windows Remote Management over HTTPS
Port 5986 is the default HTTPS listener for Windows Remote Management, carrying WS-Management and PowerShell Remoting inside TLS. The listener is tied to a service certificate identified by its thumbprint. IANA registers wsmans on TCP and UDP 5986.
Port Details
Security Exposure
TLS protects the session but does not limit who can try to log in. An internet-reachable 5986 listener accepts authentication attempts from any source, and MITRE ATT&CK T1021.006 describes adversaries using valid accounts over WinRM to run executables and modify the Registry and services on the remote host.
Hardening
- +Scope Windows Firewall rules so only management hosts can reach 5986.
- +Use certificates from a trusted internal CA and check the certificate thumbprint bound to the listener.
- +Restrict session configuration permissions to the accounts that need remote management.
- +Avoid Basic authentication, which Microsoft describes as the least secure method, and prefer Kerberos or certificate authentication.
Monitoring
Review WinRM event logs and Windows logon events for remote sessions from unexpected source hosts.
Tools for Auditing and Monitoring WinRM HTTPS
Evil-WinRM
Open SourceWinRM shell for Linux and Windows that supports authorized remote management, file transfers, and PowerShell execution during security reviews.
Sysmon
FreeWindows Sysinternals service that logs detailed process, network, and file activity to the event log.
Microsoft Defender for Endpoint
CommercialMicrosoft enterprise EDR covering Windows, macOS, Linux, and mobile from one console.
Related Tool Categories
Secrets managers, identity engines, and access control platforms for managing credentials and privilege.
Zero trust access, secure web gateways, firewalls, and perimeter enforcement platforms.
SIEM platforms, EDR agents, SOAR automation, and detection rule engines for security operations.
Frequently Asked Questions
What port does WinRM HTTPS use?→
Microsoft documents 5986 as the default HTTPS port for WinRM 2.0.
Should port 5986 be open to the internet?→
No. WinRM gives remote command execution to valid accounts, so it should be limited to management networks.
Sources
Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5986 is not guaranteed to be WinRM HTTPS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).