Important Detection 2026: PsExec-Style Remote Service Creation for Lateral Movem
Detects the creation of a remote service (Event ID 7045 or 4697) on a Windows host shortly after a remote SMB logon. The detection specifically looks for service binary paths associated with well-known lateral movement tools like PsExec (PSEXESVC), the ADMIN$ network share, or randomized executable names within the Windows Temp directory, which are common artifacts left by tools such as Impacket psexec.py and CrackMapExec.
YARA-L

