#PsExec
I bid farewell to T1 Helpdesk and assure I'll teach them what I learn. We go back to my desk.
<waves hands, but I want to emphasize my access has no standing exceptions> I get PsExec on USB.

Here's bad news.

PsExec replies it doesn't work in Safe Mode. Neither does Task Scheduler.

I'm fucked. But
July 24, 2025 at 3:14 AM
Even with tooling override there is no way to actually download PsExec through our gateway, it's too dangerous. Second, your machine would be immediately isolated harder than a a guy with leg cramps at Alcatraz.

+Guess what. Scheduled Task subsystem doesn't launch in Safe Mode.

Neither does WiFi.
July 24, 2025 at 3:08 AM
shout out Mark Russinovich btw

PsExec made my life so much easier as an admin back in the day
July 10, 2026 at 3:40 PM
What we need to do is to REG EXPORT this registry subkeys as SYSTEM. Then we need to be able to REG IMPORT them as SYSTEM.

There's two possibilities. Tools like PSEXEC that can run cmd.exe as SYSTEM or the Scheduled Tasks trick where you set a task to run as SYSTEM then manually invoke it.

However
July 24, 2025 at 3:05 AM
Instead of relying on RemCom, what if we had a python client to interact with the latest, Microsoft signed PSExec? In this post Aurélien details how he and the team did exactly this, including a tool, some PSExec internals and detection opportunities!

sensepost.com/blog/2025/ps...
February 11, 2025 at 3:25 PM
Both defenders and red teamers will be interested in this tool drop and deep dive into psexec from Aurélien.

He, Michael, and Reino built susinternals that makes use of the Microsoft signed psexec service binary on the host instead of the more easily flagged RemCom.

sensepost.com/blog/2025/ps...
SensePost | Psexec’ing the right way and why zero trust is mandatory
Leaders in Information Security
sensepost.com
February 11, 2025 at 1:22 PM
@liorbela.bsky.social
[New Post] 👉How to Prevent Malware Spread and Remote Attacks by Blocking PsExec and WMI with Intune ASR Rule - www.anoopcnair.com/how-to-preve...
🔊What Is the PsExec and WMI Blocking Rule in Intune?
#Intune #MSIntune #HTMDCommunity
November 13, 2025 at 11:56 AM
🛠️ Tool Tuesday: PsExec

Sysinternals' remote-execution classic, and the ransomware operator's deployment tool of choice. In our cases, actors use PsExec to push the locker to dozens of hosts in seconds.

🔎 Hunt tip: w…

— from @TheDFIRReport (https://x.com/TheDFIRReport/status/2102359836012806148)
DFIR Report | Discover Public Cyber Threat Intelligence Report
t.co
September 22, 2026 at 12:45 PM
New DCOM lateral movement technique discovered that bypasses traditional defenses. Unlike previous attacks relying on IDispatch interfaces, this method exploits undocumented COM interfaces within MSI, specifically targeting IMsiServer and IMsiCustomAction interfaces. 1/7
Forget PSEXEC: DCOM Upload & Execute Backdoor
Join Deep Instinct Security Researcher Eliran Nissan as he exposes a powerful new DCOM lateral movement attack that remotely writes custom payloads to create an embedded backdoor.
www.deepinstinct.com
December 12, 2024 at 12:00 AM
🛡️ 𝗣𝘀𝗘𝘅𝗲𝗰 𝘂𝗻 𝗼𝘂𝘁𝗶𝗹 𝗽𝗼𝘂𝗿 𝗹𝗲𝘀 𝗦𝘆𝘀𝗔𝗱𝗺𝗶𝗻𝘀

👉 (Re)découvrez notre tutoriel pas à pas :
www.it-connect.fr/psexec-un-ou...

💡 Gain de temps, gestion centralisée, flexibilité : un vrai allié du quotidien pour les équipes IT.

#Windows #SysAdmin #ITpro #PsExec
PsExec : un outil pour administrer Windows à distance
Dans ce tutoriel, nous allons apprendre à installer et utiliser PsExec pour exécuter des commandes et des programmes à distance sur des machines Windows.
www.it-connect.fr
August 31, 2025 at 7:01 AM
ImportExcel because you can create Excel docs on machines without MS Office installed.

invoke-CommandAs because my work banned PsExec and it allows me to run stuff as SYSTEM.
November 25, 2024 at 10:01 PM
This is fork&run to execute BOFs in a remote process, same API, and get output back over a pipe--demonstrated with Havoc.

Same arch could support explicit injection. Add-in an injector artifact + psexec, could remotely run a BOF without an agent and get output back too. bofexec? :)
December 31, 2025 at 11:51 PM
PYSA/Mespinoza Ransomware

➡️TTR 7.5 hours
➡️Koadic and Empire for C2
➡️7+ Credential Access techniques
➡️ADRecon, APS, quser, arp, and nltest for Discovery
➡️RDP and PsExec for Lateral Movement
➡️Files exfiltrated
➡️PYSA ransomware for Impact

Report link ⬇️
March 13, 2025 at 2:18 PM
Deepinstinct : DCOM Lateral movement POC abusing the IMsiServer interface - uploads and executes a payload remotely : github.com/deepinstinct...

Ref : Forget PSEXEC: DCOM Upload & Execute Backdoor : www.deepinstinct.com/blog/forget-...
December 13, 2024 at 3:06 PM
North Korean hackers (Andariel) exploit a Windows RID hijacking vulnerability for admin access. They use custom malware and open-source tools for stealthy persistence. Mitigate by monitoring LSA logs, restricting PsExec/JuicyPotato, disabling the Guest account, and using MFA.#AndarielHack
January 24, 2025 at 6:07 PM
🔧 𝗣𝘀𝗘𝘅𝗲𝗰 : l'outil que tout 𝘀𝘆𝘀𝗮𝗱𝗺𝗶𝗻 devrait maîtriser !

Découvrez comment installer et utiliser 𝗣𝘀𝗘𝘅𝗲𝗰 pour exécuter des commandes et des programmes à distance sur des machines 𝗪𝗶𝗻𝗱𝗼𝘄𝘀 🚀

👉 www.youtube.com/watch?v=dgOt...

#SysAdmin #Windows #Outils #IT #PsExec #Astuce #Tutoriel #Sécurité
PsExec : un outil d'administration très puissant !
C'est quoi PsExec ? Que peut-on faire avec PsExec ? Faut-il utiliser PsExec ou PowerShell ? Cet outil gratuit et mis à disposition sur le site de Microsoft est très puissant pour l'administration de machines Windows ! Dans cette première vidéo sur le sujet, je vous présente PsExec, vous explique comment l'installer et comment l'utiliser. Explications en français. ⭐ Sommaire 00:00 Introduction 01:12 Qu'est-ce que PsExec ? 03:09 PsExec ou PowerShell ? 05:58 Prérequis de PsExec 08:27 Télécharger et installer PsExec 10:34 Exemples d'utilisation de PsExec 18:06 Exécuter une commande PowerShell avec PsExec 20:22 Exécuter un script PowerShell avec PsExec 22:05 PsExec : récupérer une liste de cibles dans l'AD 24:50 Conclusion ⭐ Ressources : ➡️ PsExec : un outil incontournable pour les sysadmins 📌 - https://www.it-connect.fr/psexec-un-outil-incontournable-pour-les-sysadmins/ ➡️ Comment bloquer PsExec ? 📌 - https://www.it-connect.fr/comment-bloquer-psexec-voici-quelques-pistes/ Pense à t'abonner pour ne rien manquer : ⭐ https://www.youtube.com/c/It-connectFr/?sub_confirmation=1 ----- 📢🙍♂️ Auteur : Florian...
www.youtube.com
May 10, 2025 at 5:00 PM
Forget PSEXEC: DCOM Upload & Execute Backdoor www.reddit.com/r/netsec/com...
Forget PSEXEC: DCOM Upload & Execute Backdoor
www.reddit.com
December 12, 2024 at 1:51 PM
see how it's blank when I look at it, but none of those accounts are blocked or muted?

Look at the replies on those accounts

these are all bots
July 15, 2026 at 4:55 AM
How Windows Command-line Utility PsExec Can Be Abused To Execute Malicious Code
How Windows Command-line Utility PsExec Can Be Abused To Execute Malicious Code
cybersecuritynews.com
October 6, 2025 at 7:15 AM
"Complete Active Directory Takeover via AS-REP Roasting and Psexec (Scenario 2)"

medium.com/@aminouji23/...
Complete Active Directory Takeover via AS-REP Roasting and Psexec (Scenario 2)
“Complete Active Directory Takeover via AS-REP Roasting and Psexec (Scenario 2)” is published by Aminouji.
medium.com
July 15, 2025 at 4:45 PM
** How to fix Microsofts broken Edge Game Assistant **

psexec -s powershell.exe
cd "C:\Program Files\WindowsApps\Microsoft.Edge.GameAssist_1.0.3336.0_x64__8wekyb3d8bbwe"
ren EdgeGameAssist.exe EdgeGameAssist._
exit

@markrussinovich.bsky.social thx for the Sysinternals kit the 1000th time 💜
June 28, 2025 at 4:48 PM
攻撃者がVSS、PsExec、secretsdumpを悪用してActive DirectoryのNTDS.dit認証情報を窃取

攻撃者がActive Directoryドメインコントローラーを標的にし、NTDS.dITデータベースに保存された認証情報を窃取するケースが増えています。 最近実施されたシミュレーションでは、脅威アクターがWindowsのネイティブ機能、リモート管理ツール、認証情報ダンプツールを組み合わせてActive Direct
攻撃者がVSS、PsExec、secretsdumpを悪用してActive DirectoryのNTDS.dit認証情報を窃取
攻撃者がActive Directoryドメインコントローラーを標的にし、NTDS.dITデータベースに保存された認証情報を窃取するケースが増えています。 最近実施されたシミュレーションでは、脅威アクターがWindowsのネイティブ機能、リモート管理ツール、認証情報ダンプツールを組み合わせてActive Direct
blackhatnews.tokyo
September 22, 2026 at 6:18 AM
Plus it seems to be using psexec as I’ve found it in the windows folder on some PCs.

Best part? It could just be a malfunctioning dell utility or something when their app updated. With the psexec file being a red herring
February 3, 2026 at 11:55 PM
Fun fact, if the #windows ASR rule: "d1e49aac-8f56-4280-b9ba-993a6d77406c" (Block WMI/PSExec proc) is enabled, it breaks remote "Add/Remove Features" as "dismhost.exe" is launched via WMI.

You need to add an exemption to "System32\Dism" for it to work 🙃
May 23, 2026 at 8:06 PM