BIOCs
Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.
8 BIOCs match the current filters. tactic: TA0002 ✕ technique: T1569 ✕
Download CSV Show ATT&CK heatmapCommonly abused process executes by a remote host using PsExec Informational Lateral Movement
This commonly abused shell/host process was spawned by psexesvc.exe, indicating it was called by a remote host via PsExec.
Indicator:Process action type = execution AND target process name = cmd.exe , powershell.exe , powershell_ise.exe , wsmprovhost.exe , cscript.exe , wscript.exe , mshta.exe , wmic.exe , rundll32.exe , regsvr32.exe , certutil.exe , installutil.exe , msbuild.exe , ieexec.exe , dfsvc.exe , presentationhost.exe , msxsl.exe , msdt.exe , forfiles.exe , regsvcs.exe , odbcconf.exe , regasm.exe , pcalua.exe , sdiagnhost.exe , bginfo.exe , dcomcnfg.exe , dbghost.exe , cdb.exe , dnx.exe , rcsi.exe , csi.exe , windbg.exe , cdb.exe , kd.exe , cmstp.exe , fsi.exe , javaw.exe , java.exe , javac.exe , javaws.exe , jp2launcher.exe Process initiated by = psexesvc.exe , cgo name = psexesvc.exe
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)ATT&CK techniques: System Services: Service Execution (T1569.002) Remote Services: SMB/Windows Admin Shares (T1021.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Commonly abused process launches as a system service Informational Execution
This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism.
Indicator:Process action type = execution AND target process name = cmd.exe , powershell.exe , powershell_ise.exe , wsmprovhost.exe , cscript.exe , wscript.exe , mshta.exe , wmic.exe , regsvr32.exe , certutil.exe , installutil.exe , msbuild.exe , ieexec.exe , dfsvc.exe , presentationhost.exe , msxsl.exe , msdt.exe , forfiles.exe , regsvcs.exe , odbcconf.exe , regasm.exe , pcalua.exe , sdiagnhost.exe , bginfo.exe , dcomcnfg.exe , dbghost.exe , cdb.exe , dnx.exe , rcsi.exe , csi.exe , windbg.exe , cdb.exe , kd.exe , cmstp.exe , fsi.exe , javaw.exe , java.exe , javac.exe , javaws.exe , jp2launcher.exe Process os parent name = services.exe
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: System Services: Service Execution (T1569.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Malicious NetSetupSvc.dll loaded into svchost.exe Informational Dropper
A module tied to SolarStorm (TEARDROP NetSetupSvc.dll) was loaded from a malicious location into svchost.exe.
Indicator:Image Load module path = *\SysWOW64\NetSetupSvc.dll Process initiated by = svchost.exe , cgo name = svchost.exe , os parent name = svchost.exe Host host os = windows
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: System Services (T1569)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
PsExec attempts to execute a command on a remote host Informational Lateral Movement
PsExec is a SysInternals tool used to execute commands on remote hosts.
Indicator:Network action type = outgoing , failed AND remote port = 135 , 445 Process initiated by = psexec.exe AND initiator signature = Signed AND initiator signer = Microsoft Corporation Host host os = windows
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)ATT&CK techniques: Remote Services: SMB/Windows Admin Shares (T1021.002) System Services: Service Execution (T1569.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
PsExec executed with plain-text credentials on the command line Informational Execution
PsExec.exe is a Windows administrative tool, which may be used by adversaries to execute remote commands.
Indicator:Process action type = execution AND target process cmd = * -u * -p * , * -p * -u * AND target process name = psexec.exe
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: System Services: Service Execution (T1569.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
PsExec execution EulaAccepted flag added to the Registry Informational Execution
PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually.
Indicator:Registry registry key name = *\Software\Sysinternals\PsExec* AND registry value name = *EulaAccepted* AND action type = set_registry_value Process initiated by != ltsvc.exe AND batchpatch.exe AND agentservice.exe AND cgo name != ltsvc.exe AND batchpatch.exe AND agentservice.exe Host host os = windows
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)ATT&CK techniques: System Services: Service Execution (T1569.002) Remote Services: SMB/Windows Admin Shares (T1021.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-08-23
Psexesvc.exe executes a command from a remote host Informational Execution
Psexesvc.exe executes to run a command received from a remote host via PsExec.
Indicator:Process action type = execution AND target process name = psexesvc.exe AND process execution signature = Signed AND process execution signer = Microsoft Corporation Host host os = windows
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: System Services: Service Execution (T1569.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11
Remote command executed from a Linux host Low Lateral Movement
This tool enables commands to be remotely executed on a Microsoft Windows computer from a Linux computer. This capability is leveraged by attackers to run code remotely, similarly to PsExec.
Indicator:Process action type = execution AND target process name = winexesvc.exe , winexe.exe
ATT&CK tactics: Execution (TA0002)ATT&CK techniques: System Services: Service Execution (T1569.002)- Preventable:
- Yes
- Source:
- Palo Alto Networks
- Updated:
- 2026-02-11