Rules Contributing to Suspicious PsExec Execution Alert

The following rules detect suspicious SMB traffic related to PsExec Execution activities. Any one or more of these will trigger the Suspicious PsExec Execution Alert. Details for each rule can be viewed by clicking the More Details link in the description.

Title

Description

Suspicious PsExec Execution

detects execution of psexec or paexec with renamed service name, this rule helps to filter out the noise if psexec is used for legit purposes or if attacker uses a different psexec client other than sysinternal one