Back to Rule

Rule History

SID: 2010781 • Source: et/open

Versions (3)

Version DetailsCurrent

Rev: 3Jul 30, 2010, 12:00 PM

ET POLICY PsExec service created

alert tcp any any -> $HOME_NET [139,445] (msg:"ET POLICY PsExec service created"; flow:to_server,established; content:"P|00|S|00|E|00|X|00|E|00|S|00|V|00|C"; nocase; reference:url,xinn.org/Snort-psexec.html; classtype:suspicious-filename-detect; sid:2010781; rev:3; metadata:created_at 2010_07_30, confidence High, signature_severity Informational, updated_at 2019_07_26;)

Jul 30, 2010, 12:00 PM

Jul 26, 2019, 12:00 PM

Sep 21, 2024, 3:00 AM

May 30, 2025, 12:04 AM

rules/emerging-policy.rules