mirror of
https://github.com/splunk/security_content
synced 2026-06-08 17:32:49 +00:00
Update detect_psexec_with_accepteula_flag.yml
This commit is contained in:
@@ -11,7 +11,7 @@ description: The following analytic identifies the execution of `PsExec.exe` wit
|
||||
This activity is significant because PsExec is commonly used by threat actors to
|
||||
execute code on remote systems, and the `accepteula` flag indicates first-time usage,
|
||||
which could signify initial compromise. If confirmed malicious, this activity could
|
||||
allow attackers to gain remote code execution capabilities, potentially leading
|
||||
allow attackers to gain remote code execution capabilities, potentially leading
|
||||
to further system compromise and lateral movement within the network.
|
||||
data_source:
|
||||
- Sysmon EventID 1
|
||||
|
||||
Reference in New Issue
Block a user