For the complete documentation index, see llms.txt. This page is also available as Markdown.

PsExec was executed with a suspicious command line

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent

ATT&CK Tactic

Execution (TA0002), Privilege Escalation (TA0004)

ATT&CK Technique

System Services: Service Execution (T1569.002), Valid Accounts (T1078)

Severity

Informational

Description

PsExec.exe was executed.

Attacker's Goals

An adversary may attempt to use PsExec to gain execution capabilities, run remote commands or perform privilege escalation.

Investigative actions

  • Check if any other suspicious activities happened under the same causality.

  • Confirm the PsExec.exe command is benign.

Variations

PsExec was executed with a suspicious command line by a LOLBIN

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002), Privilege Escalation (TA0004)

ATT&CK Technique

System Services: Service Execution (T1569.002), Valid Accounts (T1078)

Severity

Low

Description

PsExec.exe was executed with NT/System privilege level by a LOLBIN.

Attacker's Goals

An adversary may attempt to use PsExec to gain execution capabilities, run remote commands or perform privilege escalation.

Investigative actions

  • Check if any other suspicious activities happened under the same causality.

  • Confirm the PsExec.exe command is benign.

PsExec was executed with a suspicious command line by an unsigned actor

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002), Privilege Escalation (TA0004)

ATT&CK Technique

System Services: Service Execution (T1569.002), Valid Accounts (T1078)

Severity

Medium

Description

PsExec.exe was executed with NT/System privilege level by an unsigned actor.

Attacker's Goals

An adversary may attempt to use PsExec to gain execution capabilities, run remote commands or perform privilege escalation.

Investigative actions

  • Check if any other suspicious activities happened under the same causality.

  • Confirm the PsExec.exe command is benign.

PsExec was executed with a suspicious command line

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002), Privilege Escalation (TA0004)

ATT&CK Technique

System Services: Service Execution (T1569.002), Valid Accounts (T1078)

Severity

Low

Description

PsExec.exe was executed with NT/System privilege level.

Attacker's Goals

An adversary may attempt to use PsExec to gain execution capabilities, run remote commands or perform privilege escalation.

Investigative actions

  • Check if any other suspicious activities happened under the same causality.

  • Confirm the PsExec.exe command is benign.

PsExec was executed with a suspicious command line

Synopsis

Field
Value

ATT&CK Tactic

Execution (TA0002), Privilege Escalation (TA0004)

ATT&CK Technique

System Services: Service Execution (T1569.002), Valid Accounts (T1078)

Severity

Low

Description

PsExec.exe was executed with plain-text credentials.

Attacker's Goals

An adversary may attempt to use PsExec to gain execution capabilities, run remote commands or perform privilege escalation.

Investigative actions

  • Check if any other suspicious activities happened under the same causality.

  • Confirm the PsExec.exe command is benign.

Was this helpful?