MITRE ATT&CK

PsExec is a Sysinternals tool developed by Microsoft for remote code execution and lateral movement. It enables administrators to execute commands on remote systems by connecting to the hidden ADMIN$ share and leveraging the Service Control Manager. Because it’s digitally signed and commonly used by system administrators, attackers often abuse PsExec to stealthily copy and execute malicious binaries on target systems.


How Attackers Use It


Detection

Screenshot 2025-03-02 053254.png

Important Windows Event Logs

Important Sysmon Event IDs


Threat Hunting