BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category
  • PsExec runs with System privileges Informational Privilege Escalation

    PsExec.exe is a Windows administrative tool, it can be used to elevate privileges and run other processes with NT/System privilege level.

    Indicator:

    Process action type = execution AND target process cmd = * -s* AND target process name = psexec.exe

    ATT&CK tactics: Privilege Escalation (TA0004)
    ATT&CK techniques: Valid Accounts (T1078)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11