Picus Security A.I CyberSecurity Scoring
Picus Security
Company Information
Website:http://www.picussecurity.com
Employees number:307
Number of followers:52,241
NAICS:541514
Industry Type:Computer and Network Security
Homepage:picussecurity.com
Picus Security Risk Score (AI oriented)
Between 700 and 749
Picus SecurityComputer and Network Security
Updated:
10/08/2026
10/08/2026
737/1000
Moderate
Ba
Picus Security Global Score (TPRM)
xxxx
Picus SecurityComputer and Network Security
Score locked

Picus SecurityModerate
Current Score
737Ba (MODERATE)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
754
Cyber Attack
10 Aug 2026 • Picus Security
Picus Security and Play Ransomware Group: Play Ransomware Masquerades as PsExec to Blend Into Legitimate Windows Administration
Play Ransomware Exploits PsExec Disguise to Evade Detection
737
CRITICAL-17
PLAPIC1786364786
Play Ransomware Exploits PsExec Disguise to Evade Detection
The Play ransomware group has adopted a deceptive tactic to blend into legitimate Windows administration activity, using a custom binary named PSexesvc.exe a near-identical mimic of Microsoft Sysinternals’ PsExec tool. This masquerading technique (MITRE ATT&CK T1036) allows attackers to execute lateral movement and payload deployment while evading suspicion, as the binary appears routine to defenders.
The malware has been observed staging tools and ransom notes in C:\Users\Public\Music\, a seemingly innocuous directory that may go unnoticed during investigations. Play also leverages genuine PsExec and Windows Management Instrumentation (WMI) for lateral movement, complicating detection efforts by blending malicious activity with legitimate administrative workflows.
Recent findings from Picus Security highlight Play’s evasion prowess, ranking it as the least-prevented ransomware family in 2026 simulations, with only 13% of its attack techniques blocked by production security controls. The analysis, based on aggregated testing of real-world attack chains, underscores a critical gap: organizations often deploy endpoint, network, and logging tools but fail to detect the behavioral sequences ransomware operators exploit.
Key evasion techniques employed by Play and other low-prevention families include:
- Obfuscated files (T1027): Encrypting payloads and configurations to bypass static scanners.
- Security tool tampering: Disabling or modifying defenses.
- Process injection, registry modification, and reflective code loading.
- Signed binary abuse: Leveraging trusted executables for proxy execution.
For defenders, behavioral detection is critical. Security teams should prioritize monitoring for:
- Remote execution (PsExec, WMI, PowerShell, RDP).
- Suspicious service creation (e.g., PSexesvc launched from user-writable directories like Public\Music).
- Abrupt service stoppages, Event Log clearing, or shadow-copy deletion.
- Anomalous encryption activity in the same timeframe.
Mitigation recommendations align with CISA’s Play ransomware advisory, emphasizing:
- Reducing remote-access exposure and patching internet-facing services.
- Enforcing MFA for privileged and remote accounts.
- Network segmentation and restricting administrative tools to approved hosts.
- Offline backups to mitigate encryption impacts.
The broader takeaway: detection coverage on paper does not equal prevention in practice. Organizations must validate defenses against real-world attack chains, baselining approved workflows and correlating telemetry across endpoints, authentication logs, and network events. While banning PsExec outright is impractical, defenders should ensure its abuse is visible, attributable, and actionable.
INCIDENT DETAILS -
TYPE
MOTIVATION
REFERENCES
JULY 2026
754
JUNE 2026
754
MAY 2026
754
APRIL 2026
754
MARCH 2026
754
FEBRUARY 2026
754
JANUARY 2026
754
DECEMBER 2025
754
NOVEMBER 2025
754
OCTOBER 2025
754
SEPTEMBER 2025
754
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Picus Security ??
What was Picus Security's A.I Rankiteo Cyber Score in July 2026 ??
What was Picus Security's A.I Rankiteo Cyber Score in June 2026 ??
What was Picus Security's A.I Rankiteo Cyber Score in May 2026 ??
What was Picus Security's A.I Rankiteo Cyber Score in April 2026 ??
What was Picus Security's A.I Rankiteo Cyber Score in March 2026 ??
What was Picus Security's A.I Rankiteo Cyber Score in February 2026 ??
What was Picus Security's A.I Rankiteo Cyber Score in January 2026 ??
What was Picus Security's A.I Rankiteo Cyber Score in December 2025 ??
What was Picus Security's A.I Rankiteo Cyber Score in November 2025 ??
What was Picus Security's A.I Rankiteo Cyber Score in October 2025 ??
What was Picus Security's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on Picus Security's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Picus Security ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Picus Security's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?