ATT&CKReferencesPsExec Russinovich

PsExec Russinovich

Russinovich, M. (2004, June 28). PsExec. Retrieved December 17, 2015.

Open the source

Techniques0

Not cited by any technique.

Groups0

None recorded.

Software0

None recorded.

Campaigns0

None recorded.

Procedure examples4

TechniqueUsed byProcedure example
T1021.002
SMB/Windows Admin Shares
MalwareOlympic Destroyer

Olympic Destroyer uses PsExec to interact with the ADMIN$ network share to execute commands on remote systems.

T1021.002
SMB/Windows Admin Shares
ToolPsExec

PsExec, a tool that has been used by adversaries, writes programs to the ADMIN$ network share to execute commands on remote systems.

T1021.002
SMB/Windows Admin Shares
MalwareNotPetya

NotPetya can use PsExec, which interacts with the ADMIN$ network share to execute commands on remote systems.

T1570
Lateral Tool Transfer
ToolPsExec

PsExec can be used to download or upload a file over a network share.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.