Windows PsExec Service Binary Renamed Execution via psexesvc.exe

Alerts when psexesvc.exe is executed from a non-standard path, suggesting renamed or relocated PsExec service usage.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-07-21
Updated
2026-07-30

What it detects

This rule flags process creation where the executable reports OriginalFileName as psexesvc.exe, but the launched image is not C:\Windows\PSEXESVC.exe. Renamed or relocated service binaries are a common way to evade allowlists and blend into unusual execution paths, so this pattern can indicate attacker-controlled execution. The detection relies on Windows process creation telemetry including OriginalFileName and the full Image path.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.