PsExec Service Creation or Modification
Detects the creation or modification of services associated with PsExec, a legitimate tool often abused by adversaries for remote execution. The rule looks for specific service names or file paths indicative of PsExec activity, including the default 'PSEXESVC' service name, or file paths containing 'ADMIN$' or 'IPC$' shares, or a randomly named executable in the SystemRoot directory. It filters out activity from designated administrative workstations and common system accounts.
Microsoft Sentinel (KQL)

