
PsExec Detection Cheat Sheet
Telemetry sources, sigma-style detection logic and false-positive patterns for PsExec lateral movement.
How do you detect PsExec lateral movement?
PsExec leaves a consistent trail — service creation on the target host, named-pipe activity, writes to admin shares, and the matching authentication events. Detection pairs those telemetry sources with rules tuned against the legitimate administrative use that produces most false positives. Macksofy builds detection content like this into the SOCs it runs.
PsExec is a Sysinternals tool — and an attacker's lateral-movement workhorse. Most mid-market SOCs miss it because the detections that ship by default fire on something every IT admin uses anyway. This cheat sheet lists the telemetry sources, the sigma-style logic and the false-positive patterns that separate IT-admin PsExec from adversary PsExec.
Telemetry sources
- Windows Security log: 4624 (logon), 4688 (process), 4697 (service install), 5145 (network share access)
- Sysmon: 1 (process), 3 (network connection), 11 (file create), 13 (registry value set)
- EDR process telemetry — most critical, ties parent → child reliably
- Network telemetry — SMB to ADMIN$ from a non-admin source
Sigma-style high-fidelity detections
| Behavior | Signal | Confidence |
|---|---|---|
| PSEXESVC service install on remote host | Event 4697 with ServiceName=PSEXESVC OR ServiceFileName ending psexesvc.exe | High |
| psexesvc.exe process spawned | Sysmon EID 1, Image ends \psexesvc.exe, ParentImage=services.exe | High |
| ADMIN$ share access from non-admin source | Event 5145, ShareName=\\*\ADMIN$, AccessRequest=WriteData | Medium |
| Cmd / PowerShell as child of psexesvc | Sysmon EID 1, ParentImage ends \psexesvc.exe, Image ends \cmd.exe OR \powershell.exe | High — investigate immediately |
| Anonymous pipe usage from psexesvc | Sysmon EID 17/18 (pipe events), PipeName matches PSEXESVC pattern | Medium — useful for variant detection |
False-positive sources
- Legitimate IT-admin remediation runs — burn an exception list keyed by source host + admin user account.
- RMM tools (ConnectWise, Kaseya, NinjaOne) using PsExec under the hood — exception by parent process and code-sign.
- Patch-management vendors that wrap PsExec — usually pinned source IPs, easy to except.
PsExec variants and impostors
- Renamed psexesvc.exe — file-hash detection beats name-only detection.
- Custom forks (Ms-Wbt-Server, RemCom) use the same SCM + ADMIN$ technique — detect on the technique, not the binary.
- PsExec-style behavior implemented inside Cobalt Strike beacons — pivot to EDR command-line + parent telemetry.
Service install via SCM + a 4-letter random name + a binary in C:\Windows\ that wasn't there 60 seconds ago is the technique. Whether the file is psexesvc.exe or x9q4.exe, the SCM-install + temp-binary pattern is the high-confidence detection.
Macksofy offers full-service engagements that map directly to this resource. Common starting points:
