Skip to content
Threat Feed

Tag

Psexec

5 briefs RSS
medium advisory

Potential WSUS Abuse for Lateral Movement via PsExec

Adversaries may exploit Windows Server Update Services (WSUS) to execute PsExec for lateral movement within a network by abusing the trusted update mechanism to run signed binaries.

Windows Server Update Services lateral-movement wsus psexec windows
2r 2t
medium advisory

Potential WSUS Abuse for Lateral Movement via PsExec

This rule detects potential abuse of Windows Server Update Services (WSUS) for lateral movement by identifying suspicious processes, specifically PsExec, initiated by WSUS (wuauclt.exe).

Windows Server Update Services lateral-movement windows wsus psexec
2r 2t
medium advisory

Suspicious Process Execution via Renamed PsExec Executable

The rule identifies suspicious PsExec activity where the psexec service is executed from a renamed executable, possibly to evade detection and enable lateral movement.

PsExec +1 lateral-movement defense-evasion windows
2r 3t
low advisory

PsExec Lateral Movement via Network Connection

The rule identifies the use of PsExec.exe making a network connection, indicative of potential lateral movement by adversaries executing commands with SYSTEM privileges on Windows systems to disable defenses.

Elastic Defend +1 psexec lateral-movement windows
2r 3t
medium advisory

Suspicious Process Execution via Renamed PsExec Executable

Detects suspicious PsExec activity where the PsExec service component is executed using a custom name, indicating an attempt to evade detections that look for the default PsExec service component name.

Elastic Defend +2 psexec lateral-movement execution defense-evasion windows
2r 3t