Title:Sysinternals PsService Execution Status:test Description:Detects usage of Sysinternals PsService which can be abused for service reconnaissance and tampering References: -https://learn.microsoft.com/en-us/sysinternals/downloads/psservice Author: Nasreddine Bencherchali (Nextron Systems) Date: 2022-06-16 modified:2026-06-29 Tags:
-'attack.privilege-escalation'
-'attack.discovery'
-'attack.persistence'
-'attack.t1543.003'
Logsource:
category: process_creation
product: windows
Detection: selection: OriginalFileName:'psservice.exe'- Image|endswith: - '\PsService.exe' - '\PsService64.exe' - '\PsService64a.exe' condition:selection Falsepositives:
-Legitimate use of PsService by an administrator Level:medium