Analytics BIOC Informational

PsExec was executed with a suspicious command line

PsExec.exe was executed.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002) Privilege Escalation (TA0004)
ATT&CK techniques: System Services: Service Execution (T1569.002) Valid Accounts (T1078)
Attacker's goals:

An adversary may attempt to use PsExec to gain execution capabilities, run remote commands or perform privilege escalation.

Investigative actions:

Check if any other suspicious activities happened under the same causality. Confirm the PsExec.exe command is benign.

Test period:
N/A (single event)
Deduplication:
1 Day
4 variations:
  • PsExec was executed with a suspicious command line by a LOLBIN Low (parent: Informational)
  • PsExec was executed with a suspicious command line by an unsigned actor Medium (parent: Informational)
  • PsExec was executed with a suspicious command line Low (parent: Informational)
  • PsExec was executed with a suspicious command line Low (parent: Informational)