Analytics BIOC
Informational
✕
PsExec was executed with a suspicious command line
PsExec.exe was executed.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Execution (TA0002) Privilege Escalation (TA0004)
ATT&CK techniques: System Services: Service Execution (T1569.002) Valid Accounts (T1078)
Attacker's goals:
An adversary may attempt to use PsExec to gain execution capabilities, run remote commands or perform privilege escalation.
Investigative actions:
Check if any other suspicious activities happened under the same causality. Confirm the PsExec.exe command is benign.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
4 variations:
- PsExec was executed with a suspicious command line by a LOLBIN Low (parent: Informational)
- PsExec was executed with a suspicious command line by an unsigned actor Medium (parent: Informational)
- PsExec was executed with a suspicious command line Low (parent: Informational)
- PsExec was executed with a suspicious command line Low (parent: Informational)