Skip to main content

Port Details

Port
5986
Transport
TCP
Service
WinRM HTTPS
IANA service name
wsmans
Range
User port (1024-49151)
Related ports

Security Exposure

TLS protects the session but does not limit who can try to log in. An internet-reachable 5986 listener accepts authentication attempts from any source, and MITRE ATT&CK T1021.006 describes adversaries using valid accounts over WinRM to run executables and modify the Registry and services on the remote host.

Hardening

  • +Scope Windows Firewall rules so only management hosts can reach 5986.
  • +Use certificates from a trusted internal CA and check the certificate thumbprint bound to the listener.
  • +Restrict session configuration permissions to the accounts that need remote management.
  • +Avoid Basic authentication, which Microsoft describes as the least secure method, and prefer Kerberos or certificate authentication.

Monitoring

Review WinRM event logs and Windows logon events for remote sessions from unexpected source hosts.

Tools for Auditing and Monitoring WinRM HTTPS

Evil-WinRM

Open Source
Penetration Testing Tools

WinRM shell for Linux and Windows that supports authorized remote management, file transfers, and PowerShell execution during security reviews.

LicenseLGPL-3.0-only
PlatformLinux, Windows

Sysmon

Free
SIEM Tools

Windows Sysinternals service that logs detailed process, network, and file activity to the event log.

LicenseProprietary
PlatformWindows
SIEM Tools

Microsoft enterprise EDR covering Windows, macOS, Linux, and mobile from one console.

LicenseProprietary
PlatformWindows, macOS, Linux, iOS, Android, Web

Frequently Asked Questions

What port does WinRM HTTPS use?→

Microsoft documents 5986 as the default HTTPS port for WinRM 2.0.

Should port 5986 be open to the internet?→

No. WinRM gives remote command execution to valid accounts, so it should be limited to management networks.

Sources

Port assignments from the IANA Service Name and Transport Protocol Port Number Registry. Services can be configured to run on any port, so traffic on port 5986 is not guaranteed to be WinRM HTTPS. Exploited-in-the-wild data from the CISA KEV catalog (CC0).