Analytics BIOC
Informational
✕
Remote PsExec-like command execution
A remotely triggered service initiated a command execution in a PsExec-like manner by a host that rarely triggers services to other remote hosts.
- Module:
- Platform Analytics
- Data source:
- XDR Agent
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
ATT&CK techniques: Remote Services (T1021) System Services: Service Execution (T1569.002) Lateral Tool Transfer (T1570)
Detector tags: Impacket Analytics
Attacker's goals:
Perform lateral movement to new hosts to expand the foothold within a network.
Investigative actions:
Investigate the processes being spawned on the host for malicious activities. Correlate the RPC call from the source host and understand which software initiated it.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
5 variations:
- Remote PsExec-like LOLBIN command execution from an unsigned non-standard PsExec service High (parent: Informational)
- Remote PsExec-like LOLBIN command execution from a signed non-standard PsExec service Medium (parent: Informational)
- Remote PsExec-like command execution from an unsigned non-standard PsExec service Medium (parent: Informational)
- Remote PsExec-like command execution from a signed non-standard PsExec service Low (parent: Informational)
- Remote PsExec command execution Low (parent: Informational)