Most Popular Detection 2026 – PsExec-Style Remote Service Creation via SMB Admin Shares
Detects the creation of suspicious Windows services associated with remote execution tools like PsExec, PAExec, or custom tools that leverage SMB administrative shares (ADMIN$, IPC$). The rule correlates the service creation event (Event ID 7045, 4697) with preceding network connection attempts to SMB shares, and subsequent service termination or state change events within a short timeframe, which is a pattern characteristic of remote lateral movement and command execution.
Cortex XDR

