BIOC Informational

PsExec execution EulaAccepted flag added to the Registry

PsExec is commonly used by malware for lateral movement, seeing this value in the Registry means that the user ran PsExec and approved the EULA either automatically or manually.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Execution
Status:
Enabled
ATT&CK tactics: Lateral Movement (TA0008) Execution (TA0002)
ATT&CK techniques: System Services: Service Execution (T1569.002) Remote Services: SMB/Windows Admin Shares (T1021.002)
Indicator:

Registry registry key name = *\Software\Sysinternals\PsExec* AND registry value name = *EulaAccepted* AND action type = set_registry_value Process initiated by != ltsvc.exe AND batchpatch.exe AND agentservice.exe AND cgo name != ltsvc.exe AND batchpatch.exe AND agentservice.exe Host host os = windows

Preventable: yes