Suspicious PsExec Execution - Zeek (f1b3a22a-45e6-4004-afb5-4291f9c21166)
detects execution of psexec or paexec with renamed service name, this rule helps to filter out the noise if psexec is used for legit purposes or if attacker uses a different psexec client other than sysinternal one