Attempt to execute a command on a remote host using PsExec.exe

Cortex XDR Analytics Alert Reference by data source

Last date published
2024-04-15
Order
data source

Synopsis

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

  • Requires:
    • XDR Agent

Detection Modules

ATT&CK Tactic

ATT&CK Technique

Severity

Low

Description

There was an attempt to run a command on a remote host using PsExec.exe.

Attacker's Goals

Execute commands and run processes remotely.

Investigative actions

Confirm that the connection is benign and occurred as a part of normal behavior.

Variations

Attempt to execute a command on a remote host using PsExec.exe

Synopsis

ATT&CK Tactic

ATT&CK Technique

Severity

Low

Description

There was an attempt to run a command on a remote host using PsExec.exe., the connection to the remote host was successful.

Attacker's Goals

Execute commands and run processes remotely.

Investigative actions

Confirm that the connection is benign and occurred as a part of normal behavior.