Update detect_psexec_with_accepteula_flag.yml

This commit is contained in:
Bhavin Patel
2025-04-21 13:00:03 -07:00
committed by GitHub
parent 366474792d
commit b5258b99e4
@@ -11,7 +11,7 @@ description: The following analytic identifies the execution of `PsExec.exe` wit
This activity is significant because PsExec is commonly used by threat actors to
execute code on remote systems, and the `accepteula` flag indicates first-time usage,
which could signify initial compromise. If confirmed malicious, this activity could
allow attackers to gain remote code execution capabilities, potentially leading
allow attackers to gain remote code execution capabilities, potentially leading
to further system compromise and lateral movement within the network.
data_source:
- Sysmon EventID 1