Potential PsExec Remote Execution

 Original Source: [Sigma source]
Title: Potential PsExec Remote Execution
Status: test
Description:Detects potential psexec command that initiate execution on a remote systems via common commandline flags used by the utility
References:
  -https://learn.microsoft.com/en-us/sysinternals/downloads/psexec
  -https://www.poweradmin.com/paexec/
  -https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html
Author: Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)
Date: 2023-02-28
modified:2025-09-01
Tags:
  • -'attack.resource-development'
  • -'attack.t1587.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
    CommandLine|contains|all:
      -'accepteula'
      -' -u '
      -' -p '
      -' \\\\'

  filter_main_localhost:
    CommandLine|contains:
      -'\\\\localhost'
      -'\\\\127.'

  condition:selection and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: high