Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0552 — Detection of Windows Service Creation or Modification
DET0552

Detection of Windows Service Creation or Modification

1 analytic(s) · 1 technique(s) detected

Analytics

1
AN1527 Analytic 1527
Windows

Detects creation or modification of Windows Services through command-line tools (e.g., `sc.exe`, `powershell.exe`), Registry key changes under `HKLM\System\CurrentControlSet\Services`, and service execution under SYSTEM with unsigned or anomalous binary paths. Detects privilege escalation via driver installation or `CreateServiceW` usage. Correlates parent-child lineage, startup behavior, and rare service names.

WinEventLog:Security EventCode=4697 WinEventLog:Sysmon EventCode=1 WinEventLog:Sysmon EventCode=13, 14 WinEventLog:Sysmon EventCode=6
[ServiceNamePattern] Regex for suspicious or uncommon service names (e.g., `svhostx`, `winhelp`, etc.)
[ImagePathFilter] Flag services whose image path resides in uncommon directories (e.g., `C:\Users\`, `C:\Temp\`)
[DriverExtensionList] Watch for `.sys` files loaded by `sc`, Registry, or `ZwLoadDriver` APIs
[StartupTypeChangeWindow] Temporal window to correlate Registry `Start` key changes with service creation
[UnsignedBinaryAlert] Raise alerts for unsigned binaries registered as services

Detected Techniques

1

Details

MITRE ID
DET0552
STIX ID
x-mitre-detection-strategy--c7d19c6f-a7f8-4323-af57-c626ccb74d88
Analytics
1
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.