PsExec/Impacket-Style Lateral Movement via Admin Shares + Service Creation
Detects potential lateral movement and persistence activities by identifying suspicious Windows service installations via event ID 7045. The rule flags services with suspicious names or paths (e.g., Temp folders, Public directory) and correlates them with incoming SMB connections (port 445) or services spawned directly by services.exe from suspicious locations, aggregated by host and remote IP.
Cortex XDR

