PsExec Service Child Process Execution as LOCAL SYSTEM
Description
Detects suspicious launch of the PSEXESVC service on this system and a sub process run as LOCAL_SYSTEM (-s), which means that someone remotely started a command on this system running it with highest privileges and not only the privileges of the login user account (e.g. the administrator account)
Query · sigma
selection: ParentImage: C:\Windows\PSEXESVC.exe User|contains: - AUTHORI - AUTORI condition: selection
Known false positives
- Users that debug Microsoft Intune issues using the commands mentioned in the official documentation; see https://learn.microsoft.com/en-us/mem/intune/apps/intune-management-extension