Smbexec Installed As Service - Security

Rule Info

Name
Smbexec Installed As Service - Security
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects the installation of the impacket's smbexec service on a target system. When smbexec is executed, it creates a new service with specific patterns.
Date
2025-02-06 00:00:00
Modified
None
Id
6eabb5b3-66c2-47d7-ab12-cfffb1bc56a4
Tags
attack.lateral-movement attack.execution attack.t1021.002 attack.t1569.002
Type
Nextron Sigma feed only (private)

Rule History