Windows PsExec Service Execution via PSEXESVC.exe

Detects PsExec service execution by matching the PSEXESVC.exe process on Windows.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
Thomas Patzke, Romaissa Adjailia, Florian Roth (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2017-06-12
Updated
2026-07-30

What it detects

This rule flags process creation where C:\Windows\PSEXESVC.exe runs, corresponding to use of the PsExec service component for remote execution. Attackers can leverage this to execute commands on a remote Windows host in a way that blends into administrative tooling. Telemetry relies on Windows process creation events capturing the full image path and the OriginalFileName field.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.