Attempt to execute a command on a remote host using PsExec.exe
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Malicious Service Analytics
ATT&CK Tactic
Lateral Movement (TA0008), Execution (TA0002)
ATT&CK Technique
Remote Services: SMB/Windows Admin Shares (T1021.002), System Services: Service Execution (T1569.002)
Severity
Low
Description
There was an attempt to run a command on a remote host using PsExec.exe.
Attacker's Goals
Execute commands and run processes remotely.
Investigative actions
Confirm that the connection is benign and occurred as a part of normal behavior.
Variations
PreviousAppleScript process executed with a rare command line
NextAttempted Azure application access from unknown tenant
Was this helpful?
