title: Sysinternals PsService Execution id: 3371f518-5fe3-4cf6-a14b-2a0ae3fd8a4f status: test description: Detects usage of Sysinternals PsService which can be abused for service reconnaissance and tampering references: - https://learn.microsoft.com/en-us/sysinternals/downloads/psservice author: Nasreddine Bencherchali (Nextron Systems) date: 2022-06-16 modified: 2023-02-24 tags: - attack.discovery - attack.persistence - attack.t1543.003 logsource: category: process_creation product: windows detection: selection: - OriginalFileName: 'psservice.exe' - Image|endswith: - '\PsService.exe' - '\PsService64.exe' condition: selection falsepositives: - Legitimate use of PsService by an administrator level: medium