Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

PsExec is a free Microsoft Sysinternals command-line utility for running programs locally or on remote Windows computers. Mark Russinovich created PsExec and is credited as its author in Microsoft’s documentation. It is legitimate administration software—not malware—but its ability to copy files, create a temporary service, and execute remotely is also routinely abused for lateral movement and ransomware.

This guide explains what PsExec does, how to use its important options safely, why credentials and sessions cause confusion, and when PowerShell remoting or an endpoint-management platform is a better choice.

What PsExec is—and is not

PsExec is part of Microsoft’s PsTools collection. It can start console programs on the local computer or a reachable remote Windows host without requiring an administrator to preinstall a conventional client agent. Microsoft’s current page lists PsExec version 2.43, supports Windows 8.1 and later as a client, and Windows Server 2012 and later as a server: official documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

It is a lightweight execution utility, not a remote-desktop replacement. RDP and remote-support products provide a graphical desktop; PowerShell remoting provides structured automation; Intune, Configuration Manager, and RMM platforms provide fleet management, reporting, scheduling, and policy.

Who is Mark Russinovich?

Russinovich co-founded Sysinternals, which began in 1996 as a site for advanced Windows utilities and technical information. Microsoft later acquired Sysinternals. He is associated with Windows internals and Microsoft Azure leadership, and Microsoft’s author information identifies him as a Sysinternals and Winternals co-founder. See Microsoft’s Sysinternals overview and author biography. PsExec remains a Microsoft Sysinternals utility; it is not a separate commercial product named after Russinovich.

How PsExec works

For an authorized remote operation, the conceptual sequence is:

  1. You run psexec.exe and authenticate with the current account or supplied credentials.
  2. PsExec uses Windows remote-administration mechanisms, including administrative shares and the Service Control Manager.
  3. With -c, it copies the selected executable to the remote computer, commonly through an administrative share.
  4. A temporary Windows service can launch the requested process. MITRE maps this behavior to Service Execution and documents PsExec’s use of ADMIN$.
  5. For interactive use, PsExec connects the remote process’s console to yours.
  6. Cleanup normally follows, although artifacts and timing can vary with version, policy, and failure conditions.
Administrator console
        │ authenticate and connect
        ▼
Remote Windows host ── administrative share / service ──► requested process
        ▲                                                   │
        └──────────── optional console redirection ────────┘

This design is why PsExec can be useful to administrators and suspicious to defenders at the same time.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Install and verify it

Download PsExec only from Microsoft’s Sysinternals page or the official Sysinternals distribution. Extract the PsTools archive, invoke the executable by full path, or place it in a controlled directory on your executable path. Run:

psexec -?

On first use you may see a license prompt; -accepteula suppresses it for approved automation and -nobanner removes the startup banner. Verify the downloaded file’s digital signature and provenance before permitting it through security controls.

Useful commands and switches

Option Purpose Important caution
computer Choose a remote computer; omit it for local execution. Confirm the target before running.
computer1,computer2 / @file Run against several named hosts or a target file. One typo can affect many systems.
-u user Specify an account, commonly DomainUser. Use least privilege.
-p password Supply a password. It can leak through history, scripts, process inspection, or logs; omit it to receive a prompt where practical.
-i [session] Attach the process to an interactive user session. The session must exist and be the intended one.
-c Copy a local executable to the remote host. Without it, the executable must already be available remotely.
-f / -v Force copying, or copy only when the local file is newer or has a higher version. -f can overwrite the remote copy.
-d Do not wait for the process to finish. You lose immediate completion status.
-s Run as the remote SYSTEM account. Highly privileged; not a security bypass.
-h Use an elevated token when available. Relevant to UAC and administrator tokens.
-l Run with limited-user privileges. Useful for reducing privilege.
-e Do not load the user profile. Environment variables and profile settings may differ.
-w directory Set the remote working directory. The directory is on the remote host.
-r service-name Choose the remote service name. Useful for naming control or avoiding collisions.
-n seconds Set the connection timeout. Prevents indefinite waits.

These definitions and syntax are documented by Microsoft: PsExec reference.

Safe, authorized examples

Use these only on systems you own or are explicitly authorized to administer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Check a remote host

psexec \PC01 hostname

The output should be the target computer’s hostname.

Open an interactive command prompt

psexec -i \PC01 cmd.exe

-i connects the process to a user session. If you do not need interaction, omit it.

Run a diagnostic

psexec -i \PC01 ipconfig /all

Copy and run an approved tool

psexec -i \PC01 -c C:Toolsinventory.exe

Here C:Toolsinventory.exe is on the source computer. The -c switch copies it before execution; it is not a license to run untrusted downloads.

Run locally as SYSTEM

psexec -i -s cmd.exe

Use this for documented diagnostics or recovery. Confirm the identity with whoami, and remember that SYSTEM’s profile, network access, and desktop context differ from yours.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Accounts, paths, profiles, and sessions

If no username is supplied, PsExec uses the current account context on the remote computer. A process can run successfully yet fail to reach a file share because its remote impersonation context has no delegated network credentials. Microsoft discusses these credential and logon-type considerations in its privileged-access guidance.

Remote execution also changes the environment:

  • Mapped drives may not exist. Use a properly authorized UNC path instead.
  • A local path is not automatically a remote path. Use -c, or specify a path that exists on the target.
  • The working directory can be set with -w.
  • -e changes profile loading and therefore environment variables and application behavior.
  • -i needs the correct session; a GUI started in another session may be invisible.
  • Running as SYSTEM changes permissions and desktop interaction, but does not defeat firewall, policy, or endpoint security.

Microsoft says the password and command are encrypted in transit, but encryption does not make hard-coded passwords safe. Prefer prompting, delegated access, or an approved secrets-management workflow over putting reusable privileged credentials in batch files.

Troubleshooting by symptom

“Access is denied”

Check the target name, network reachability, account rights, UAC remote restrictions, local and domain policy, service-management permissions, and EDR blocks. Review Security, System, and endpoint-security logs on both machines. Do not solve a single-host problem by granting broad domain-admin rights.

The executable cannot be found

Without -c, PsExec expects the program to be available to the remote computer. A source-side C:Toolsapp.exe does not exist there merely because it exists locally.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The GUI does not appear

Verify that a user is logged on, identify the correct session, add -i, and test with a console command first. Session isolation and SYSTEM’s separate desktop can prevent visible windows.

The command hangs

The program may be waiting for input, displaying a hidden dialog, or requiring interaction. Test with hostname or another short command. Use -d only when another method can verify completion.

It works locally but not remotely

Compare identity, profile, working directory, drive mappings, network credentials, UAC, and security policy. Remote execution is a different context, not simply a longer local command line.

Antivirus or EDR blocks it

Confirm the official source, signature, hash, initiating account, target, command, and approval. Coordinate with security operations; do not create a blanket exclusion. Microsoft notes that PsTools are legitimate but are often used by malware.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Why attackers use PsExec

PsExec’s administrative features map directly to attacker techniques: MITRE’s PsExec profile covers remote execution, administrative-share use, file transfer, lateral movement, and service-based execution. Threat actors and ransomware groups have used PsExec-like workflows to move between systems and launch programs under privileged accounts.

A PsExec detection is therefore not automatically proof of malware. It is a high-value context signal: investigate who launched it, from which workstation, against which hosts, with what command, and whether the action was approved. A tampered copy from an unofficial site is a different and more serious problem than the verified Microsoft utility.

What defenders should monitor

  • Unexpected Windows service creation, including Security event 4697.
  • services.exe spawning unusual processes and short-lived service lifecycles.
  • Files written to ADMIN$ or other administrative shares.
  • Sysmon process creation event 1, registry events 13 and 14, and network event 3 where Sysmon is deployed.
  • Remote execution from unusual administrator workstations or by accounts that rarely administer endpoints.
  • Activity targeting domain controllers and other high-value systems.
  • Rapid execution across many hosts, especially outside a change window.

MITRE’s detection strategy details relevant telemetry. Microsoft Defender’s attack-surface-reduction documentation includes a rule to block process creations originating from PsExec and WMI; test such a control in audit mode and against legitimate workflows before enforcement: ASR guidance. Blocking PsExec alone cannot eliminate lateral movement because similar behavior can be produced through other Windows services, WMI, PowerShell, or APIs.

When to choose PsExec—or something else

Need Better fit
One-off command on a reachable Windows host PsExec
Repeatable scripts and structured output PowerShell remoting / WinRM
Software deployment, compliance, and reporting across a fleet Intune, Configuration Manager, or equivalent
Persistent monitoring, patching, and remote support An RMM or endpoint-management platform
Full graphical desktop assistance RDP or approved remote-support software
Incident-response execution PsExec only under documented, approved procedures with enhanced logging

PsExec is a good fit when a small, controlled action must happen quickly and Windows administrative access is already configured. It is a poor fit for disconnected internet endpoints, thousands of devices, approval workflows, rollback, inventory, or least-privilege governance that requires a centralized platform.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

Bottom line: PsExec is a legitimate Microsoft Sysinternals tool authored by Mark Russinovich, but its remote-service and administrative-share behavior is inherently dual-use. Verify the official binary, use the least privilege necessary, avoid exposing passwords, log every remote action, and choose PowerShell remoting or a managed endpoint platform when the job is larger than a controlled command.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.