PsExec SYSTEM Shell Followed by Shadow Copy Activity
This rule detects a suspicious sequence of activities indicative of potential lateral movement and credential access. It identifies the execution of PsExec (PSEXESVC.exe) in conjunction with volume shadow copy manipulation (vssadmin, wmic, or diskshadow to create or delete shadow copies) within a 30-minute window. It further correlates this activity with potential lateral movement commands (e.g., net.exe, query.exe, nslookup.exe) to assess the severity of the incident.
Microsoft Sentinel (KQL)

