LoFP LoFP / rare legitimate use of psexec from the locations mentioned above. this will require initial tuning based on your environment.

Techniques

Sample rules

PsExec Tool Execution From Suspicious Locations - PipeName

Description

Detects PsExec default pipe creation where the image executed is located in a suspicious location. Which could indicate that the tool is being used in an attack

Detection logic

condition: selection
selection:
  Image|contains:
  - :\Users\Public\
  - :\Windows\Temp\
  - \AppData\Local\Temp\
  - \Desktop\
  - \Downloads\
  PipeName: \PSEXESVC