Metasploit Or Impacket Service Installation Via SMB PsExec — Detection Rule

Detects usage of Metasploit SMB PsExec (exploit/windows/smb/psexec) and Impacket psexec.py by triggering on specific service installation

Read the full analysis on IntelFusions