Title:
Metasploit Or Impacket Service Installation Via SMB PsExec
Status:
test
Description:Detects usage of Metasploit SMB PsExec (exploit/windows/smb/psexec) and Impacket psexec.py by triggering on specific service installation
References:
-https://bczyz1.github.io/2021/01/30/psexec.html
Author: Bartlomiej Czyz, Relativity
Date: 2021-01-21
modified:2022-10-05
Tags:
- -'attack.lateral-movement'
- -'attack.t1021.002'
- -'attack.t1570'
- -'attack.execution'
- -'attack.t1569.002'
Logsource:
- product: windows
- service: security
- definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
Detection:
selection:
EventID:
'4697'
ServiceFileName|re:
'^%systemroot%\\[a-zA-Z]{8}\.exe$'
ServiceName|re:
'(^[a-zA-Z]{4}$)|(^[a-zA-Z]{8}$)|(^[a-zA-Z]{16}$)'
ServiceStartType:
'3'
ServiceType:
'0x10'
filter:
ServiceName:
'PSEXESVC'
condition:
selection and not filter
Falsepositives:
-Possible, different agents with a 8 character binary and a 4, 8 or 16 character service name
Level:
high