From b5258b99e41002a72f84fdc57e4002df3bc284a3 Mon Sep 17 00:00:00 2001 From: Bhavin Patel Date: Mon, 21 Apr 2025 13:00:03 -0700 Subject: [PATCH] Update detect_psexec_with_accepteula_flag.yml --- detections/endpoint/detect_psexec_with_accepteula_flag.yml | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/detections/endpoint/detect_psexec_with_accepteula_flag.yml b/detections/endpoint/detect_psexec_with_accepteula_flag.yml index 8208b3197e..5643d865a3 100644 --- a/detections/endpoint/detect_psexec_with_accepteula_flag.yml +++ b/detections/endpoint/detect_psexec_with_accepteula_flag.yml @@ -11,7 +11,7 @@ description: The following analytic identifies the execution of `PsExec.exe` wit This activity is significant because PsExec is commonly used by threat actors to execute code on remote systems, and the `accepteula` flag indicates first-time usage, which could signify initial compromise. If confirmed malicious, this activity could - allow attackers to gain remote code execution capabilities, potentially leading + allow attackers to gain remote code execution capabilities, potentially leading to further system compromise and lateral movement within the network. data_source: - Sysmon EventID 1