Analytics BIOC Informational

Remote PsExec-like command execution

A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
ATT&CK techniques: Remote Services (T1021) System Services: Service Execution (T1569.002) Lateral Tool Transfer (T1570)
Detector tags: Impacket Analytics
Attacker's goals:

Perform lateral movement to new hosts to expand the foothold within a network.

Investigative actions:

Investigate the processes being spawned on the host for malicious activities. Correlate the RPC call from the source host and understand which software initiated it.

Test period:
N/A (single event)
Deduplication:
1 Day
5 variations:
  • Remote PsExec-like LOLBIN command execution from an unsigned non-standard PsExec service High (parent: Informational)
  • Remote PsExec-like LOLBIN command execution from a signed non-standard PsExec service Medium (parent: Informational)
  • Remote PsExec-like command execution from an unsigned non-standard PsExec service Medium (parent: Informational)
  • Remote PsExec-like command execution from a signed non-standard PsExec service Low (parent: Informational)
  • Remote PsExec command execution Low (parent: Informational)