Elastic medium stable eql
Suspicious Process Execution via Renamed PsExec Executable
Identifies suspicious psexec activity which is executing from the psexec service that has been renamed, possibly to evade detection.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
process.pe.original_file_name : "psexesvc.exe" and not process.name : "PSEXESVC.exe" Field Validations
Loading…
Comments (0)
Loading comments...