During a routine log triage, an EDR system flags an administrator account executing PsExec across multiple internal network segments. What must be confirmed first before declaring this event a definitive system compromise?
Make the call. Every option has a note waiting here.
Notes on all 4 options
- AThe number of hosts touched describes scope, but large or small, it does not tell you whether the activity was authorized.
- BPsExec is legitimately signed by Microsoft Sysinternals, so its signature says nothing about whether this use is malicious.
- CCorrect: administrators use PsExec routinely, so checking change tickets and scheduled maintenance first separates normal IT work from lateral movement.
- DEncoded PowerShell is a useful indicator but is secondary; it does not establish whether the activity was sanctioned.