{"id":"T1543.003","name":"Windows Service","url":"https://attack.mitre.org/techniques/T1543/003","tactics":["persistence","privilege-escalation"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0552","stix_id":"x-mitre-detection-strategy--c7d19c6f-a7f8-4323-af57-c626ccb74d88","name":"Detection of Windows Service Creation or Modification","url":"https://attack.mitre.org/detectionstrategies/DET0552","analytics":[{"id":"AN1527","stix_id":"x-mitre-analytic--ffaa281c-dd99-486d-bc7f-225580f784f4","name":"Analytic 1527","description":"Detects creation or modification of Windows Services through command-line tools (e.g., `sc.exe`, `powershell.exe`), Registry key changes under `HKLM\\System\\CurrentControlSet\\Services`, and service execution under SYSTEM with unsigned or anomalous binary paths. Detects privilege escalation via driver installation or `CreateServiceW` usage. Correlates parent-child lineage, startup behavior, and rare service names.","url":"https://attack.mitre.org/detectionstrategies/DET0552#AN1527","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4697","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=6","data_component":"DC0079","data_component_name":"Driver Load","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ServiceNamePattern","description":"Regex for suspicious or uncommon service names (e.g., `svhostx`, `winhelp`, etc.)"},{"field":"ImagePathFilter","description":"Flag services whose image path resides in uncommon directories (e.g., `C:\\Users\\`, `C:\\Temp\\`)"},{"field":"DriverExtensionList","description":"Watch for `.sys` files loaded by `sc`, Registry, or `ZwLoadDriver` APIs"},{"field":"StartupTypeChangeWindow","description":"Temporal window to correlate Registry `Start` key changes with service creation"},{"field":"UnsignedBinaryAlert","description":"Raise alerts for unsigned binaries registered as services"}],"live":true,"detection_strategies":["DET0552"],"techniques":["T1543.003"]}],"live":true,"version":"1.0","techniques":["T1543.003"]}],"sigma_rules":[{"id":"05296024-fe8a-4baf-8f3d-9a5f5624ceb2","title":"Malicious Driver Load","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-18","modified":"2023-12-02","description":"Detects loading of known malicious drivers via their hash.","references":["https://loldrivers.io/"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003","attack.t1068"],"path":"rules/windows/driver_load/driver_load_win_mal_drivers.yml","techniques":["T1543.003","T1068"],"cves":[]},{"id":"1228f8e2-7e79-4dea-b0ad-c91f1d5016c1","title":"Turla PNG Dropper Service","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2018-11-23","modified":"2021-11-30","description":"This method detects malicious services mentioned in Turla PNG dropper report by NCC Group in November 2018","references":["https://research.nccgroup.com/2018/11/22/turla-png-dropper-is-back/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.privilege-escalation","attack.persistence","attack.g0010","attack.t1543.003","detection.emerging-threats"],"path":"rules-emerging-threats/2017/TA/Turla/win_system_apt_turla_service_png.yml","techniques":["T1543.003"],"cves":[]},{"id":"138d3531-8793-4f50-a2cd-f291b2863d78","title":"Suspicious Service Path Modification","author":"Victor Sergeev, oscd.community, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2019-10-21","modified":"2022-11-18","description":"Detects service path modification via the \"sc\" binary to a suspicious command or path","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1543.003/T1543.003.md","https://web.archive.org/web/20180331144337/https://www.fireeye.com/blog/threat-research/2018/03/sanny-malware-delivery-method-updated-in-recently-observed-attacks.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/process_creation/proc_creation_win_sc_service_path_modification.yml","techniques":["T1543.003"],"cves":[]},{"id":"17a1be64-8d88-40bf-b5ff-a4f7a50ebcc8","title":"Suspicious New Service Creation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-07-14","modified":"2022-11-18","description":"Detects creation of a new service via \"sc\" command or the powershell \"new-service\" cmdlet with suspicious binary paths","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1543.003/T1543.003.md","https://web.archive.org/web/20180331144337/https://www.fireeye.com/blog/threat-research/2018/03/sanny-malware-delivery-method-updated-in-recently-observed-attacks.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/process_creation/proc_creation_win_susp_service_creation.yml","techniques":["T1543.003"],"cves":[]},{"id":"1a31b18a-f00c-4061-9900-f735b96c99fc","title":"Remote Access Tool Services Have Been Installed - System","author":"Connor Martin, Nasreddine Bencherchali","status":"test","level":"medium","date":"2022-12-23","modified":"2023-06-22","description":"Detects service installation of different remote access tools software. These software are often abused by threat actors to perform","references":["https://redcanary.com/blog/misbehaving-rats/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_remote_access_software.yml","techniques":["T1543.003","T1569.002"],"cves":[]},{"id":"1a42dfa6-6cb2-4df9-9b48-295be477e835","title":"Vulnerable WinRing0 Driver Load","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-07-26","modified":"2024-11-23","description":"Detects the load of a signed WinRing0 driver often used by threat actors, crypto miners (XMRIG) or malware for privilege escalation","references":["https://github.com/xmrig/xmrig/tree/master/bin/WinRing0","https://www.rapid7.com/blog/post/2021/12/13/driver-based-attacks-past-and-present/"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/driver_load/driver_load_win_vuln_winring0_driver.yml","techniques":["T1543.003"],"cves":[]},{"id":"1b2ae822-6fe1-43ba-aa7c-d1a3b3d1d5f2","title":"Service Installation with Suspicious Folder Pattern","author":"pH-T (Nextron Systems)","status":"test","level":"high","date":"2022-03-18","modified":"2022-03-24","description":"Detects service installation with suspicious folder patterns","references":["Internal Research"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.privilege-escalation","car.2013-09-005","attack.t1543.003"],"path":"rules/windows/builtin/system/service_control_manager/win_system_susp_service_installation_folder_pattern.yml","techniques":["T1543.003"],"cves":[]},{"id":"1d61f71d-59d2-479e-9562-4ff5f4ead16b","title":"Suspicious Service Installation","author":"pH-T (Nextron Systems), Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-03-18","modified":"2023-12-04","description":"Detects suspicious service installation commands","references":["Internal Research"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.privilege-escalation","car.2013-09-005","attack.t1543.003"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_susp.yml","techniques":["T1543.003"],"cves":[]},{"id":"1df8b3da-b0ac-4d8a-b7c7-6cb7c24160e4","title":"Turla Service Install","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-03-31","modified":"2021-11-30","description":"This method detects a service install of malicious services mentioned in Carbon Paper - Turla report by ESET","references":["https://www.welivesecurity.com/2017/03/30/carbon-paper-peering-turlas-second-stage-backdoor/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.privilege-escalation","attack.persistence","attack.g0010","attack.t1543.003","detection.emerging-threats"],"path":"rules-emerging-threats/2017/TA/Turla/win_system_apt_carbonpaper_turla.yml","techniques":["T1543.003"],"cves":[]},{"id":"25b9c01c-350d-4b95-bed1-836d04a4f324","title":"Moriya Rootkit - System","author":"Bhabesh Raj","status":"test","level":"critical","date":"2021-05-06","modified":"2022-11-29","description":"Detects the use of Moriya rootkit as described in the securelist's Operation TunnelSnake report","references":["https://securelist.com/operation-tunnelsnake-and-moriya-rootkit/101831"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/builtin/system/service_control_manager/win_system_moriya_rootkit.yml","techniques":["T1543.003"],"cves":[]},{"id":"26481afe-db26-4228-b264-25a29fe6efc7","title":"Uncommon Service Installation Image Path","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2022-03-18","modified":"2024-02-09","description":"Detects uncommon service installation commands by looking at suspicious or uncommon image path values containing references to encoded powershell commands, temporary paths, etc.\n","references":["Internal Research"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.privilege-escalation","car.2013-09-005","attack.t1543.003"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_uncommon.yml","techniques":["T1543.003"],"cves":[]},{"id":"295c9289-acee-4503-a571-8eacaef36b28","title":"Vulnerable HackSys Extreme Vulnerable Driver Load","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-18","modified":"2024-11-23","description":"Detects the load of HackSys Extreme Vulnerable Driver which is an intentionally vulnerable Windows driver developed for security enthusiasts to learn and polish their exploitation skills at Kernel level and often abused by threat actors","references":["https://github.com/hacksysteam/HackSysExtremeVulnerableDriver"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/driver_load/driver_load_win_vuln_hevd_driver.yml","techniques":["T1543.003"],"cves":[]},{"id":"2c4523d5-d481-4ed0-8ec3-7fbf0cb41a75","title":"Driver Load From A Temporary Directory","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-02-12","modified":"2021-11-27","description":"Detects a driver load from a temporary directory","references":["Internal Research"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/driver_load/driver_load_win_susp_temp_use.yml","techniques":["T1543.003"],"cves":[]},{"id":"304afd73-55a5-4bb9-8c21-0b1fc84ea9e4","title":"PSEXEC Remote Execution File Artefact","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-21","modified":"2023-02-23","description":"Detects creation of the PSEXEC key file. Which is created anytime a PsExec command is executed. It gets written to the file system and will be recorded in the USN Journal on the target system","references":["https://aboutdfir.com/the-key-to-identify-psexec/","https://twitter.com/davisrichardg/status/1616518800584704028"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.lateral-movement","attack.privilege-escalation","attack.execution","attack.persistence","attack.t1136.002","attack.t1543.003","attack.t1570","attack.s0029"],"path":"rules/windows/file/file_event/file_event_win_sysinternals_psexec_service_key.yml","techniques":["T1136.002","T1543.003","T1570"],"cves":[]},{"id":"31c51af6-e7aa-4da7-84d4-8f32cc580af2","title":"Sliver C2 Default Service Installation","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-25","modified":null,"description":"Detects known malicious service installation that appear in cases in which a Sliver implants execute the PsExec commands","references":["https://github.com/BishopFox/sliver/blob/79f2d48fcdfc2bee4713b78d431ea4b27f733f30/client/command/commands.go#L1231","https://www.microsoft.com/security/blog/2022/08/24/looking-for-the-sliver-lining-hunting-for-emerging-command-and-control-frameworks/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_sliver.yml","techniques":["T1543.003","T1569.002"],"cves":[]},{"id":"3371f518-5fe3-4cf6-a14b-2a0ae3fd8a4f","title":"Sysinternals PsService Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-06-16","modified":"2026-06-29","description":"Detects usage of Sysinternals PsService which can be abused for service reconnaissance and tampering","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/psservice"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.discovery","attack.persistence","attack.t1543.003"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_psservice.yml","techniques":["T1543.003"],"cves":[]},{"id":"38879043-7e1e-47a9-8d46-6bec88e201df","title":"Potential Persistence Attempt Via Existing Service Tampering","author":"Sreeman","status":"test","level":"medium","date":"2020-09-29","modified":"2023-02-04","description":"Detects the modification of an existing service in order to execute an arbitrary payload when the service is started or killed as a potential method for persistence.","references":["https://pentestlab.blog/2020/01/22/persistence-modify-existing-service/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.stealth","attack.t1543.003","attack.t1574.011"],"path":"rules/windows/process_creation/proc_creation_win_sc_service_tamper_for_persistence.yml","techniques":["T1543.003","T1574.011"],"cves":[]},{"id":"39b64854-5497-4b57-a448-40977b8c9679","title":"Malicious Driver Load By Name","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-10-03","modified":"2023-12-02","description":"Detects loading of known malicious drivers via the file name of the drivers.","references":["https://loldrivers.io/"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003","attack.t1068"],"path":"rules/windows/driver_load/driver_load_win_mal_drivers_names.yml","techniques":["T1543.003","T1068"],"cves":[]},{"id":"431a1fdb-4799-4f3b-91c3-a683b003fc49","title":"New Kernel Driver Via SC.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-07-14","modified":"2025-10-07","description":"Detects creation of a new service (kernel driver) with the type \"kernel\"","references":["https://www.aon.com/cyber-solutions/aon_cyber_labs/yours-truly-signed-av-driver-weaponizing-an-antivirus-driver/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/process_creation/proc_creation_win_sc_new_kernel_driver.yml","techniques":["T1543.003"],"cves":[]},{"id":"48bbc537-b652-4b4e-bd1d-281172df448f","title":"Sysinternals PsSuspend Execution","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-03-23","modified":"2026-06-29","description":"Detects usage of Sysinternals PsSuspend which can be abused to suspend critical processes","references":["https://learn.microsoft.com/en-us/sysinternals/downloads/pssuspend","https://twitter.com/0gtweet/status/1638069413717975046"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.discovery","attack.persistence","attack.t1543.003"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_pssuspend_execution.yml","techniques":["T1543.003"],"cves":[]},{"id":"53ba33fd-3a50-4468-a5ef-c583635cfa92","title":"OilRig APT Schedule Task Persistence - System","author":"Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community","status":"test","level":"critical","date":"2018-03-23","modified":"2023-03-08","description":"Detects OilRig schedule task persistence as reported by Nyotron in their March 2018 report","references":["https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf"],"logsource":{"product":"windows","service":"system"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.defense-impairment","attack.g0049","attack.t1053.005","attack.s0111","attack.t1543.003","attack.t1112","attack.command-and-control","attack.t1071.004","detection.emerging-threats"],"path":"rules-emerging-threats/2018/TA/OilRig/win_system_apt_oilrig_mar18.yml","techniques":["T1053.005","T1543.003","T1112","T1071.004"],"cves":[]},{"id":"5a105d34-05fc-401e-8553-272b45c1522d","title":"CobaltStrike Service Installations - System","author":"Florian Roth (Nextron Systems), Wojciech Lesicki","status":"test","level":"critical","date":"2021-05-26","modified":"2022-11-27","description":"Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement","references":["https://www.sans.org/webcasts/119395","https://www.crowdstrike.com/blog/getting-the-bacon-from-cobalt-strike-beacon/","https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.lateral-movement","attack.t1021.002","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_cobaltstrike_service_installs.yml","techniques":["T1021.002","T1543.003","T1569.002"],"cves":[]},{"id":"5e993621-67d4-488a-b9ae-b420d08b96cb","title":"Service Installation in Suspicious Folder","author":"pH-T (Nextron Systems)","status":"test","level":"medium","date":"2022-03-18","modified":"2024-01-18","description":"Detects service installation in suspicious folder appdata","references":["Internal Research"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.privilege-escalation","car.2013-09-005","attack.t1543.003"],"path":"rules/windows/builtin/system/service_control_manager/win_system_susp_service_installation_folder.yml","techniques":["T1543.003"],"cves":[]},{"id":"612e47e9-8a59-43a6-b404-f48683f45bd6","title":"ServiceDll Hijack","author":"frack113","status":"test","level":"medium","date":"2022-02-04","modified":"2024-04-03","description":"Detects changes to the \"ServiceDLL\" value related to a service in the registry.\nThis is often used as a method of persistence.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1543.003/T1543.003.md#atomic-test-4---tinyturla-backdoor-service-w64time","https://www.hexacorn.com/blog/2013/09/19/beyond-good-ol-run-key-part-4/"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/registry/registry_set/registry_set_servicedll_hijack.yml","techniques":["T1543.003"],"cves":[]},{"id":"61a7697c-cb79-42a8-a2ff-5f0cdfae0130","title":"Potential CobaltStrike Service Installations - Registry","author":"Wojciech Lesicki","status":"test","level":"high","date":"2021-06-29","modified":"2024-03-25","description":"Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement.\n","references":["https://www.sans.org/webcasts/tech-tuesday-workshop-cobalt-strike-detection-log-analysis-119395"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.lateral-movement","attack.t1021.002","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/registry/registry_set/registry_set_cobaltstrike_service_installs.yml","techniques":["T1021.002","T1543.003","T1569.002"],"cves":[]},{"id":"6c8fbee5-dee8-49bc-851d-c3142d02aa47","title":"Allow Service Access Using Security Descriptor Tampering Via Sc.EXE","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-02-28","modified":"2025-10-22","description":"Detects suspicious DACL modifications to allow access to a service from a suspicious trustee. This can be used to override access restrictions set by previous ACLs.","references":["https://twitter.com/0gtweet/status/1628720819537936386","https://itconnect.uw.edu/tools-services-support/it-systems-infrastructure/msinf/other-help/understanding-sddl-syntax/","https://learn.microsoft.com/en-us/windows/win32/secauthz/sid-strings"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1543.003"],"path":"rules/windows/process_creation/proc_creation_win_sc_sdset_allow_service_changes.yml","techniques":["T1543.003"],"cves":[]},{"id":"70f00d10-60b2-4f34-b9a0-dc3df3fe762a","title":"Suspicious Service Installation Script","author":"pH-T (Nextron Systems)","status":"test","level":"high","date":"2022-03-18","modified":"2024-03-05","description":"Detects suspicious service installation scripts","references":["Internal Research"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.privilege-escalation","car.2013-09-005","attack.t1543.003"],"path":"rules/windows/builtin/system/service_control_manager/win_system_susp_service_installation_script.yml","techniques":["T1543.003"],"cves":[]},{"id":"710bdbce-495d-491d-9a8f-7d0d88d2b41e","title":"Special File Creation via Mknod Syscall","author":"Milad Cheraghi","status":"experimental","level":"low","date":"2025-05-31","modified":"2025-12-05","description":"Detects usage of the `mknod` syscall to create special files (e.g., character or block devices).\nAttackers or malware might use `mknod` to create fake devices, interact with kernel interfaces,\nor establish covert channels in Linux systems.\nMonitoring the use of `mknod` is important because this syscall is rarely used by legitimate applications,\nand it can be abused to bypass file system restrictions or create backdoors.\n","references":["https://man7.org/linux/man-pages/man2/mknod.2.html","https://hopeness.medium.com/master-the-linux-mknod-command-a-comprehensive-guide-1c150a546aa8"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1543.003"],"path":"rules/linux/auditd/syscall/lnx_auditd_susp_special_file_creation_via_mknod_syscall.yml","techniques":["T1543.003"],"cves":[]},{"id":"72cd00d6-490c-4650-86ff-1d11f491daa1","title":"Vulnerable Driver Load By Name","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"low","date":"2022-10-03","modified":"2023-12-02","description":"Detects the load of known vulnerable drivers via the file name of the drivers.","references":["https://loldrivers.io/"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003","attack.t1068"],"path":"rules/windows/driver_load/driver_load_win_vuln_drivers_names.yml","techniques":["T1543.003","T1068"],"cves":[]},{"id":"7aaaf4b8-e47c-4295-92ee-6ed40a6f60c8","title":"Vulnerable Driver Load","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-18","modified":"2023-12-02","description":"Detects loading of known vulnerable drivers via their hash.","references":["https://loldrivers.io/"],"logsource":{"product":"windows","category":"driver_load"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003","attack.t1068"],"path":"rules/windows/driver_load/driver_load_win_vuln_drivers.yml","techniques":["T1543.003","T1068"],"cves":[]},{"id":"7bdf2a7c-3acc-4091-9581-0a77dad1c5b5","title":"OilRig APT Registry Persistence","author":"Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community","status":"test","level":"critical","date":"2018-03-23","modified":"2023-03-08","description":"Detects OilRig registry persistence as reported by Nyotron in their March 2018 report","references":["https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.defense-impairment","attack.g0049","attack.t1053.005","attack.s0111","attack.t1543.003","attack.t1112","attack.command-and-control","attack.t1071.004","detection.emerging-threats"],"path":"rules-emerging-threats/2018/TA/OilRig/registry_event_apt_oilrig_mar18.yml","techniques":["T1053.005","T1543.003","T1112","T1071.004"],"cves":[]},{"id":"85f520e7-6f5e-43ca-874c-222e5bf9c0de","title":"Devcon Execution Disabling VMware VMCI Device","author":"Matt Anderson, Dray Agha, Anna Pham (Huntress)","status":"experimental","level":"high","date":"2026-01-02","modified":null,"description":"Detects execution of devcon.exe with commands that disable the VMware Virtual Machine Communication Interface (VMCI) device.\nThis can be legitimate during VMware Tools troubleshooting or driver conflicts, but may also indicate malware attempting to hijack communication with the hardware via the VMCI device.\nThis has been used to facilitate VMware ESXi vulnerability exploits to escape VMs and execute code on the ESXi host.\n","references":["https://learn.microsoft.com/en-us/windows-hardware/drivers/devtest/devcon","https://communities.vmware.com/t5/VMware-Workstation-Pro/VMCI-driver-issues/td-p/2866060","https://github.com/search?q=devcon+disable+VMWVMCIHOSTDEV","https://huntress.com/blog/esxi-vm-escape-exploit"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.defense-impairment","attack.t1543.003","attack.t1685"],"path":"rules/windows/process_creation/proc_creation_win_devcon_disable_vmci_driver.yml","techniques":["T1543.003","T1685"],"cves":[]},{"id":"85ff530b-261d-48c6-a441-facaa2e81e48","title":"New Service Creation Using Sc.EXE","author":"Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community","status":"test","level":"low","date":"2023-02-20","modified":"2025-09-01","description":"Detects the creation of a new service using the \"sc.exe\" utility.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1543.003/T1543.003.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/process_creation/proc_creation_win_sc_create_service.yml","techniques":["T1543.003"],"cves":[]},{"id":"99cf1e02-00fb-4c0d-8375-563f978dfd37","title":"Deny Service Access Using Security Descriptor Tampering Via Sc.EXE","author":"Jonhnathan Ribeiro, oscd.community","status":"test","level":"high","date":"2020-10-16","modified":"2023-02-28","description":"Detects suspicious DACL modifications to deny access to a service that affects critical trustees. This can be used to hide services or make them unstoppable.","references":["https://www.sans.org/blog/red-team-tactics-hiding-windows-services/","https://itconnect.uw.edu/tools-services-support/it-systems-infrastructure/msinf/other-help/understanding-sddl-syntax/","https://learn.microsoft.com/en-us/windows/win32/secauthz/sid-strings"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1543.003"],"path":"rules/windows/process_creation/proc_creation_win_sc_sdset_deny_service_access.yml","techniques":["T1543.003"],"cves":[]},{"id":"9e987c6c-4c1e-40d8-bd85-dd26fba8fdd6","title":"StoneDrill Service Install","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2017-03-07","modified":"2021-11-30","description":"This method detects a service install of the malicious Microsoft Network Realtime Inspection Service service described in StoneDrill report by Kaspersky","references":["https://securelist.com/blog/research/77725/from-shamoon-to-stonedrill/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.privilege-escalation","attack.persistence","attack.g0064","attack.t1543.003","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Malware/StoneDrill/win_system_apt_stonedrill.yml","techniques":["T1543.003"],"cves":[]},{"id":"a1507d71-0b60-44f6-b17c-bf53220fdd88","title":"Moriya Rootkit File Created","author":"Bhabesh Raj","status":"test","level":"critical","date":"2021-05-06","modified":"2023-05-05","description":"Detects the creation of a file named \"MoriyaStreamWatchmen.sys\" in a specific location. This filename was reported to be related to the Moriya rootkit as described in the securelist's Operation TunnelSnake report.","references":["https://securelist.com/operation-tunnelsnake-and-moriya-rootkit/101831"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Malware/Moriya-Rootkit/file_event_win_moriya_rootkit.yml","techniques":["T1543.003"],"cves":[]},{"id":"a95b9b42-1308-4735-a1af-abb1c5e6f5ac","title":"Suspicious Service DACL Modification Via Set-Service Cmdlet","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-10-18","modified":null,"description":"Detects suspicious DACL modifications via the \"Set-Service\" cmdlet using the \"SecurityDescriptorSddl\" flag (Only available with PowerShell 7) that can be used to hide services or make them unstopable","references":["https://www.sans.org/blog/red-team-tactics-hiding-windows-services/","https://learn.microsoft.com/pt-br/windows/win32/secauthz/sid-strings"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1543.003"],"path":"rules/windows/process_creation/proc_creation_win_powershell_service_dacl_modification_set_service.yml","techniques":["T1543.003"],"cves":[]},{"id":"b98a10af-1e1e-44a7-bab2-4cc026917648","title":"New PDQDeploy Service - Client Side","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-07-22","modified":null,"description":"Detects PDQDeploy service installation on the target system.\nWhen a package is deployed via PDQDeploy it installs a remote service on the target machine with the name \"PDQDeployRunner-X\" where \"X\" is an integer starting from 1\n","references":["https://documentation.pdq.com/PDQDeploy/13.0.3.0/index.html?windows-services.htm"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_pdqdeploy_runner.yml","techniques":["T1543.003"],"cves":[]},{"id":"c02e96b7-c63a-4c47-bd83-4a9f74afcfb2","title":"New Service Creation Using PowerShell","author":"Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community","status":"test","level":"low","date":"2023-02-20","modified":null,"description":"Detects the creation of a new service using powershell.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1543.003/T1543.003.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/process_creation/proc_creation_win_powershell_create_service.yml","techniques":["T1543.003"],"cves":[]},{"id":"c0580559-a6bd-4ef6-b9b7-83703d98b561","title":"OilRig APT Schedule Task Persistence - Security","author":"Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community","status":"test","level":"critical","date":"2018-03-23","modified":"2023-03-08","description":"Detects OilRig schedule task persistence as reported by Nyotron in their March 2018 report","references":["https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.defense-impairment","attack.g0049","attack.t1053.005","attack.s0111","attack.t1543.003","attack.t1112","attack.command-and-control","attack.t1071.004","detection.emerging-threats"],"path":"rules-emerging-threats/2018/TA/OilRig/win_security_apt_oilrig_mar18.yml","techniques":["T1053.005","T1543.003","T1112","T1071.004"],"cves":[]},{"id":"c4ff1eac-84ad-44dd-a6fb-d56a92fc43a9","title":"ProcessHacker Privilege Elevation","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-05-27","modified":"2022-12-25","description":"Detects a ProcessHacker tool that elevated privileges to a very high level","references":["https://twitter.com/1kwpeter/status/1397816101455765504"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_pua_proceshacker.yml","techniques":["T1543.003","T1569.002"],"cves":[]},{"id":"c8b00925-926c-47e3-beea-298fd563728e","title":"Remote Access Tool Services Have Been Installed - Security","author":"Connor Martin, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-12-23","modified":"2024-12-07","description":"Detects service installation of different remote access tools software. These software are often abused by threat actors to perform","references":["https://redcanary.com/blog/misbehaving-rats/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/security/win_security_service_install_remote_access_software.yml","techniques":["T1543.003","T1569.002"],"cves":[]},{"id":"cb062102-587e-4414-8efa-dbe3c7bf19c6","title":"CosmicDuke Service Installation","author":"Florian Roth (Nextron Systems), Daniil Yugoslavskiy, oscd.community (update)","status":"test","level":"critical","date":"2017-03-27","modified":"2022-10-09","description":"Detects the installation of a service named \"javamtsup\" on the system.\nThe CosmicDuke info stealer uses Windows services typically named \"javamtsup\" for persistence.\n","references":["https://blog.f-secure.com/wp-content/uploads/2019/10/CosmicDuke.pdf"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.t1543.003","attack.t1569.002","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Malware/CosmicDuke/win_security_mal_cosmik_duke_persistence.yml","techniques":["T1543.003","T1569.002"],"cves":[]},{"id":"ce6e34ca-966d-41c9-8d93-5b06c8b97a06","title":"OilRig APT Activity","author":"Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community","status":"test","level":"critical","date":"2018-03-23","modified":"2023-03-08","description":"Detects OilRig activity as reported by Nyotron in their March 2018 report","references":["https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.defense-impairment","attack.g0049","attack.t1053.005","attack.s0111","attack.t1543.003","attack.t1112","attack.command-and-control","attack.t1071.004","detection.emerging-threats"],"path":"rules-emerging-threats/2018/TA/OilRig/proc_creation_win_apt_oilrig_mar18.yml","techniques":["T1053.005","T1543.003","T1112","T1071.004"],"cves":[]},{"id":"d7a95147-145f-4678-b85d-d1ff4a3bb3f6","title":"CobaltStrike Service Installations - Security","author":"Florian Roth (Nextron Systems), Wojciech Lesicki","status":"test","level":"high","date":"2021-05-26","modified":"2022-11-27","description":"Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement","references":["https://www.sans.org/webcasts/119395","https://www.crowdstrike.com/blog/getting-the-bacon-from-cobalt-strike-beacon/","https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.lateral-movement","attack.t1021.002","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/security/win_security_cobaltstrike_service_installs.yml","techniques":["T1021.002","T1543.003","T1569.002"],"cves":[]},{"id":"e76ca062-4de0-4d79-8d90-160a0d335eca","title":"PUA - Kernel Driver Utility (KDU) Execution","author":"Matt Anderson, Dray Agha, Anna Pham (Huntress)","status":"experimental","level":"high","date":"2026-01-02","modified":null,"description":"Detects execution of the Kernel Driver Utility (KDU) tool.\nKDU can be used to bypass driver signature enforcement and load unsigned or malicious drivers into the Windows kernel.\nPotentially allowing for privilege escalation, persistence, or evasion of security controls.\n","references":["https://github.com/h4rmy/KDU","https://huntress.com/blog/esxi-vm-escape-exploit"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/process_creation/proc_creation_win_pua_kdu_driver_tool.yml","techniques":["T1543.003"],"cves":[]},{"id":"ee9ca27c-9bd7-4cee-9b01-6e906be7cae3","title":"New PDQDeploy Service - Server Side","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-07-22","modified":null,"description":"Detects a PDQDeploy service installation which indicates that PDQDeploy was installed on the machines.\nPDQDeploy can be abused by attackers to remotely install packages or execute commands on target machines\n","references":["https://documentation.pdq.com/PDQDeploy/13.0.3.0/index.html?windows-services.htm"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1543.003"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_pdqdeploy.yml","techniques":["T1543.003"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}