BIOC
Informational
✕
PsExec execution EulaAccepted flag added to the Registry
PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Execution
- Status:
- Enabled
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
ATT&CK techniques: System Services: Service Execution (T1569.002) Remote Services: SMB/Windows Admin Shares (T1021.002)
Indicator:
Registry registry key name = *\Software\Sysinternals\PsExec* AND registry value name = *EulaAccepted* AND action type = set_registry_value Process initiated by != ltsvc.exe AND batchpatch.exe AND agentservice.exe AND cgo name != ltsvc.exe AND batchpatch.exe AND agentservice.exe Host host os = windows
Preventable: yes