Psexec Execution

 Original Source: [Sigma source]
Title: Psexec Execution
Status: test
Description:Detects user accept agreement execution in psexec commandline
References:
  -https://www.fireeye.com/blog/threat-research/2020/10/kegtap-and-singlemalt-with-a-ransomware-chaser.html
Author: omkar72
Date: 2020-10-30
modified:2023-02-28
Tags:
  • -'attack.execution'
  • -'attack.lateral-movement'
  • -'attack.t1569'
  • -'attack.t1021'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection:
Image|endswith:'\psexec.exe' OriginalFileName:'psexec.c'   condition:selection
Falsepositives:
  -Administrative scripts.
Level: medium