LoFP LoFP / t1021.002

t1021.002

TitleTags
a file server may experience high-demand loads that could cause this analytic to trigger.
administrative scripts
administrators
administrators can leverage psexec for accessing remote systems and might pass `accepteula` as an argument if they are running this tool for the first time. however, it is not likely that you'd see multiple occurrences of this event on a machine
although uncommon, administrators may leverage impackets tools to start a process on remote systems for system administration or automation use cases.
domain controllers acting as printer servers too? :)
domain controllers that are sometimes, commonly although should not be, acting as printer servers too
false positives may occur if a user called rundll32 from cli with no options
legitimate activity by administrators and scripts
legitimate administrator activity
linux hostnames composed of 16 characters.
possible, different agents with a 8 character binary and a 4, 8 or 16 character service name
system administrators may use looks like psexec for troubleshooting or administrations tasks. however, this will typically come only from certain users and certain systems that can be added to an allow list.
unlikely
update the excluded named pipe to filter out any newly observed legit named pipe
vulnerability scanners or system administration tools may also trigger this detection. filter as needed.