PsExec

MITRE ATT&CK: S0029 View on attack.mitre.org

Aliases: PsExec

Operating systems
windows
Related IoCs
14 (4 malicious)
Last IoC activity
2026-09-03 03:38:53
Profile updated
2026-07-07 15:32:29

Context

PsExec is a free Microsoft tool that can be used to execute a program on another computer. It is used by IT administrators and attackers.

Recent IoC activity

4 malicious indicators in Maltiverse are attributed to PsExec (S0029). The 4 most recently updated:

TypeIndicatorUpdatedSources
hostname dcky6u1m8u6el.cloudfront.net 2026-09-03 2
file sample ocspackage.exe 2026-01-05 1
file sample PsExec.exe 2025-08-02 1
file sample PsExec64.exe 2025-02-15 1

Detection coverage

  • 120 Sigma rules

Malware & tools used

  • SMB/Windows Admin Shares (attack-pattern)
  • Windows Service (attack-pattern)
  • Lateral Tool Transfer (attack-pattern)
  • Service Execution (attack-pattern)
  • Domain Account (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0029 (report)
  • Microsoft — Bb897553 (report)
  • sans.org — Protecting Privileged Domain Accounts Psexec Deep Dive (report)

External references