BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category
  • Commonly abused process executes by a remote host using PsExec Informational Lateral Movement

    This commonly abused shell/host process was spawned by psexesvc.exe, indicating it was called by a remote host via PsExec.

    Indicator:

    Process action type = execution AND target process name = cmd.exe , powershell.exe , powershell_ise.exe , wsmprovhost.exe , cscript.exe , wscript.exe , mshta.exe , wmic.exe , rundll32.exe , regsvr32.exe , certutil.exe , installutil.exe , msbuild.exe , ieexec.exe , dfsvc.exe , presentationhost.exe , msxsl.exe , msdt.exe , forfiles.exe , regsvcs.exe , odbcconf.exe , regasm.exe , pcalua.exe , sdiagnhost.exe , bginfo.exe , dcomcnfg.exe , dbghost.exe , cdb.exe , dnx.exe , rcsi.exe , csi.exe , windbg.exe , cdb.exe , kd.exe , cmstp.exe , fsi.exe , javaw.exe , java.exe , javac.exe , javaws.exe , jp2launcher.exe Process initiated by = psexesvc.exe , cgo name = psexesvc.exe

    ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
    ATT&CK techniques: System Services: Service Execution (T1569.002) Remote Services: SMB/Windows Admin Shares (T1021.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Commonly abused process launches as a system service Informational Execution

    This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism.

    Indicator:

    Process action type = execution AND target process name = cmd.exe , powershell.exe , powershell_ise.exe , wsmprovhost.exe , cscript.exe , wscript.exe , mshta.exe , wmic.exe , regsvr32.exe , certutil.exe , installutil.exe , msbuild.exe , ieexec.exe , dfsvc.exe , presentationhost.exe , msxsl.exe , msdt.exe , forfiles.exe , regsvcs.exe , odbcconf.exe , regasm.exe , pcalua.exe , sdiagnhost.exe , bginfo.exe , dcomcnfg.exe , dbghost.exe , cdb.exe , dnx.exe , rcsi.exe , csi.exe , windbg.exe , cdb.exe , kd.exe , cmstp.exe , fsi.exe , javaw.exe , java.exe , javac.exe , javaws.exe , jp2launcher.exe Process os parent name = services.exe

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: System Services: Service Execution (T1569.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Malicious NetSetupSvc.dll loaded into svchost.exe Informational Dropper

    A module tied to SolarStorm (TEARDROP NetSetupSvc.dll) was loaded from a malicious location into svchost.exe.

    Indicator:

    Image Load module path = *\SysWOW64\NetSetupSvc.dll Process initiated by = svchost.exe , cgo name = svchost.exe , os parent name = svchost.exe Host host os = windows

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: System Services (T1569)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • PsExec attempts to execute a command on a remote host Informational Lateral Movement

    PsExec is a SysInternals tool used to execute commands on remote hosts.

    Indicator:

    Network action type = outgoing , failed AND remote port = 135 , 445 Process initiated by = psexec.exe AND initiator signature = Signed AND initiator signer = Microsoft Corporation Host host os = windows

    ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
    ATT&CK techniques: Remote Services: SMB/Windows Admin Shares (T1021.002) System Services: Service Execution (T1569.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • PsExec executed with plain-text credentials on the command line Informational Execution

    PsExec.exe is a Windows administrative tool, which may be used by adversaries to execute remote commands.

    Indicator:

    Process action type = execution AND target process cmd = * -u * -p * , * -p * -u * AND target process name = psexec.exe

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: System Services: Service Execution (T1569.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • PsExec execution EulaAccepted flag added to the Registry Informational Execution

    PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually.

    Indicator:

    Registry registry key name = *\Software\Sysinternals\PsExec* AND registry value name = *EulaAccepted* AND action type = set_registry_value Process initiated by != ltsvc.exe AND batchpatch.exe AND agentservice.exe AND cgo name != ltsvc.exe AND batchpatch.exe AND agentservice.exe Host host os = windows

    ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
    ATT&CK techniques: System Services: Service Execution (T1569.002) Remote Services: SMB/Windows Admin Shares (T1021.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-08-23
  • Psexesvc.exe executes a command from a remote host Informational Execution

    Psexesvc.exe executes to run a command received from a remote host via PsExec.

    Indicator:

    Process action type = execution AND target process name = psexesvc.exe AND process execution signature = Signed AND process execution signer = Microsoft Corporation Host host os = windows

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: System Services: Service Execution (T1569.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11
  • Remote command executed from a Linux host Low Lateral Movement

    This tool enables commands to be remotely executed on a Microsoft Windows computer from a Linux computer. This capability is leveraged by attackers to run code remotely, similarly to PsExec.

    Indicator:

    Process action type = execution AND target process name = winexesvc.exe , winexe.exe

    ATT&CK tactics: Execution (TA0002)
    ATT&CK techniques: System Services: Service Execution (T1569.002)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11