PHASE: PsExec Detection50% COMPLETION
Abort Mission
MODULE 06

Lateral Movement Detection

Catching PsExec, WMI abuse, and SMB/RPC anomalies.

PsExec Detection

PsExec is a legitimate tool often abused for lateral movement.

Indicators

- Service creation (PSEXESVC)
- Named pipe creation
- Admin$ share access