Offensive tool

xCmd

S0123

xCmd is an open source tool that is similar to PsExec and allows the user to execute applications on remote systems.

ATT&CK S0123 Offensive · dual-use tool
Sigma rules3 YARA rules0 Live IOCs0

Techniques Used

1
ATT&CK techniques this tool is documented performing. Each links to its detections - Sigma, vendor SIEM rules, and analytics - so you catch the behaviour even when the binary changes.

Live Indicators

Indicators are defanged for safe handling. Newest first.
External lookups - second-class, for what we don’t hold ourselves