{"id":"T1569.002","name":"Service Execution","url":"https://attack.mitre.org/techniques/T1569/002","tactics":["execution"],"platforms":["Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0421","stix_id":"x-mitre-detection-strategy--ef1996dc-b6e9-4d8b-a216-77d14323b3e5","name":"Detection Strategy for System Services Service Execution","url":"https://attack.mitre.org/detectionstrategies/DET0421","analytics":[{"id":"AN1185","stix_id":"x-mitre-analytic--fedc5a7d-4ea9-4dd7-b2e0-3f10549d90db","name":"Analytic 1185","description":"Detection focuses on abnormal service executions initiated via service control manager APIs, sc.exe, net.exe, or PsExec creating temporary services. Defenders observe process creation of services.exe spawning non-standard binaries, registry changes in service keys followed by rapid execution, and network connections originating from processes tied to transient services. Correlation across process lineage, registry activity, and service logs provides strong signals of malicious service execution.","url":"https://attack.mitre.org/detectionstrategies/DET0421#AN1185","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4697","data_component":"DC0060","data_component_name":"Service Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=13, 14","data_component":"DC0063","data_component_name":"Windows Registry Key Modification","log_source_slug":"wineventlog-sysmon"},{"name":"WinEventLog:Sysmon","channel":"EventCode=3, 22","data_component":"DC0082","data_component_name":"Network Connection Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ServiceBinaryAllowlist","description":"Known binaries/services expected to be invoked via services.exe"},{"field":"ParentProcessCorrelationWindow","description":"Time window for correlating service creation with execution events"},{"field":"RemoteExecutionHosts","description":"Approved remote hosts that may trigger service execution (e.g., via PsExec)"}],"live":true,"detection_strategies":["DET0421"],"techniques":["T1569.002"]}],"live":true,"version":"1.0","techniques":["T1569.002"]}],"sigma_rules":[{"id":"10018e73-06ec-46ec-8107-9172f1e04ff2","title":"Remote Server Service Abuse for Lateral Movement","author":"Sagie Dulce, Dekel Paz","status":"test","level":"high","date":"2022-01-01","modified":null,"description":"Detects remote RPC calls to possibly abuse remote encryption service via MS-EFSR","references":["https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-srvs/accf23b0-0f57-441c-9185-43041f1b0ee9","https://github.com/jsecurity101/MSRPC-to-ATTACK/blob/ddd4608fe8684fcf2fcf9b48c5f0b3c28097f8a3/documents/MS-SCMR.md","https://github.com/zeronetworks/rpcfirewall","https://zeronetworks.com/blog/stopping-lateral-movement-via-the-rpc-firewall/"],"logsource":{"product":"rpc_firewall","category":"application"},"tags":["attack.lateral-movement","attack.execution","attack.t1569.002"],"path":"rules/application/rpc_firewall/rpc_firewall_remote_service_lateral_movement.yml","techniques":["T1569.002"],"cves":[]},{"id":"1a31b18a-f00c-4061-9900-f735b96c99fc","title":"Remote Access Tool Services Have Been Installed - System","author":"Connor Martin, Nasreddine Bencherchali","status":"test","level":"medium","date":"2022-12-23","modified":"2023-06-22","description":"Detects service installation of different remote access tools software. These software are often abused by threat actors to perform","references":["https://redcanary.com/blog/misbehaving-rats/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_remote_access_software.yml","techniques":["T1543.003","T1569.002"],"cves":[]},{"id":"1f1d8209-636e-4c6c-a137-781cca8b82f9","title":"WFP Filter Added via Registry","author":"Frack113","status":"experimental","level":"medium","date":"2025-10-23","modified":null,"description":"Detects registry modifications that add Windows Filtering Platform (WFP) filters, which may be used to block security tools and EDR agents from reporting events.\n","references":["https://github.com/netero1010/EDRSilencer/blob/0e73a7037ec65c52894d8208e6f605a7da0a34a6/EDRSilencer.c","https://www.huntress.com/blog/silencing-the-edr-silencers","https://www.trendmicro.com/en_us/research/24/j/edrsilencer-disrupting-endpoint-security-solutions.html"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.execution","attack.defense-impairment","attack.t1685","attack.t1569.002"],"path":"rules/windows/registry/registry_set/registry_set_susp_wfp_filter_added.yml","techniques":["T1685","T1569.002"],"cves":[]},{"id":"259e5a6a-b8d2-4c38-86e2-26c5e651361d","title":"PsExec Service File Creation","author":"Thomas Patzke","status":"test","level":"low","date":"2017-06-12","modified":"2022-10-26","description":"Detects default PsExec service filename which indicates PsExec service installation and execution","references":["https://www.jpcert.or.jp/english/pub/sr/ir_research.html","https://jpcertcc.github.io/ToolAnalysisResultSheet"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.execution","attack.t1569.002","attack.s0029"],"path":"rules/windows/file/file_event/file_event_win_sysinternals_psexec_service.yml","techniques":["T1569.002"],"cves":[]},{"id":"2a072a96-a086-49fa-bcb5-15cc5a619093","title":"Start Windows Service Via Net.EXE","author":"Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community","status":"test","level":"low","date":"2019-10-21","modified":"2023-03-05","description":"Detects the usage of the \"net.exe\" command to start a service using the \"start\" flag","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1569.002/T1569.002.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1569.002"],"path":"rules/windows/process_creation/proc_creation_win_net_start_service.yml","techniques":["T1569.002"],"cves":[]},{"id":"2a926e6a-4b81-4011-8a96-e36cc8c04302","title":"PowerShell Scripts Installed as Services - Security","author":"oscd.community, Natalia Shornikova","status":"test","level":"high","date":"2020-10-06","modified":"2022-11-29","description":"Detects powershell script installed as a Service","references":["https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse"],"logsource":{"product":"windows","service":"security"},"tags":["attack.execution","attack.t1569.002"],"path":"rules/windows/builtin/security/win_security_powershell_script_installed_as_service.yml","techniques":["T1569.002"],"cves":[]},{"id":"31c51af6-e7aa-4da7-84d4-8f32cc580af2","title":"Sliver C2 Default Service Installation","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-08-25","modified":null,"description":"Detects known malicious service installation that appear in cases in which a Sliver implants execute the PsExec commands","references":["https://github.com/BishopFox/sliver/blob/79f2d48fcdfc2bee4713b78d431ea4b27f733f30/client/command/commands.go#L1231","https://www.microsoft.com/security/blog/2022/08/24/looking-for-the-sliver-lining-hunting-for-emerging-command-and-control-frameworks/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_sliver.yml","techniques":["T1543.003","T1569.002"],"cves":[]},{"id":"41504465-5e3a-4a5b-a5b4-2a0baadd4463","title":"PsExec Tool Execution From Suspicious Locations - PipeName","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-08-04","modified":"2023-09-20","description":"Detects PsExec default pipe creation where the image executed is located in a suspicious location. Which could indicate that the tool is being used in an attack","references":["https://www.jpcert.or.jp/english/pub/sr/ir_research.html","https://jpcertcc.github.io/ToolAnalysisResultSheet"],"logsource":{"product":"windows","category":"pipe_created"},"tags":["attack.execution","attack.t1569.002","attack.s0029"],"path":"rules/windows/pipe_created/pipe_created_sysinternals_psexec_default_pipe_susp_location.yml","techniques":["T1569.002"],"cves":[]},{"id":"42c575ea-e41e-41f1-b248-8093c3e82a28","title":"PsExec Service Installation","author":"Thomas Patzke","status":"test","level":"medium","date":"2017-06-12","modified":"2023-08-04","description":"Detects PsExec service installation and execution events","references":["https://www.jpcert.or.jp/english/pub/sr/ir_research.html","https://jpcertcc.github.io/ToolAnalysisResultSheet"],"logsource":{"product":"windows","service":"system"},"tags":["attack.execution","attack.t1569.002","attack.s0029"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_sysinternals_psexec.yml","techniques":["T1569.002"],"cves":[]},{"id":"4976aa50-8f41-45c6-8b15-ab3fc10e79ed","title":"Credential Dumping Tools Service Execution - System","author":"Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2017-03-05","modified":"2022-11-29","description":"Detects well-known credential dumping tools execution via service execution events","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"system"},"tags":["attack.credential-access","attack.execution","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006","attack.t1569.002","attack.s0005"],"path":"rules/windows/builtin/system/service_control_manager/win_system_mal_creddumper.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006","T1569.002"],"cves":[]},{"id":"4a5f5a5e-ac01-474b-9b4e-d61298c9df1d","title":"PowerShell as a Service in Registry","author":"oscd.community, Natalia Shornikova","status":"test","level":"high","date":"2020-10-06","modified":"2023-08-17","description":"Detects that a powershell code is written to the registry as a service.","references":["https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.execution","attack.t1569.002"],"path":"rules/windows/registry/registry_set/registry_set_powershell_as_service.yml","techniques":["T1569.002"],"cves":[]},{"id":"4e2ed651-1906-4a59-a78a-18220fca1b22","title":"PUA - NirCmd Execution","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-01-24","modified":"2023-02-13","description":"Detects the use of NirCmd tool for command execution, which could be the result of legitimate administrative activity","references":["https://www.nirsoft.net/utils/nircmd.html","https://www.winhelponline.com/blog/run-program-as-system-localsystem-account-windows/","https://www.nirsoft.net/utils/nircmd2.html#using"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1569.002","attack.s0029"],"path":"rules/windows/process_creation/proc_creation_win_pua_nircmd.yml","techniques":["T1569.002"],"cves":[]},{"id":"52a85084-6989-40c3-8f32-091e12e13f09","title":"smbexec.py Service Installation","author":"Omer Faruk Celik","status":"test","level":"high","date":"2018-03-20","modified":"2023-11-09","description":"Detects the use of smbexec.py tool by detecting a specific service installation","references":["https://blog.ropnop.com/using-credentials-to-own-windows-boxes-part-2-psexec-and-services/","https://github.com/fortra/impacket/blob/33058eb2fde6976ea62e04bc7d6b629d64d44712/examples/smbexec.py#L286-L296","https://github.com/fortra/impacket/blob/edef71f17bc1240f9f8c957bbda98662951ac3ec/examples/smbexec.py#L60"],"logsource":{"product":"windows","service":"system"},"tags":["attack.lateral-movement","attack.execution","attack.t1021.002","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_hack_smbexec.yml","techniques":["T1021.002","T1569.002"],"cves":[]},{"id":"5a105d34-05fc-401e-8553-272b45c1522d","title":"CobaltStrike Service Installations - System","author":"Florian Roth (Nextron Systems), Wojciech Lesicki","status":"test","level":"critical","date":"2021-05-26","modified":"2022-11-27","description":"Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement","references":["https://www.sans.org/webcasts/119395","https://www.crowdstrike.com/blog/getting-the-bacon-from-cobalt-strike-beacon/","https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.lateral-movement","attack.t1021.002","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_cobaltstrike_service_installs.yml","techniques":["T1021.002","T1543.003","T1569.002"],"cves":[]},{"id":"5bb68627-3198-40ca-b458-49f973db8752","title":"Rundll32 Execution Without Parameters","author":"Bartlomiej Czyz, Relativity","status":"test","level":"high","date":"2021-01-31","modified":"2023-02-28","description":"Detects rundll32 execution without parameters as observed when running Metasploit windows/smb/psexec exploit module","references":["https://bczyz1.github.io/2021/01/30/psexec.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.lateral-movement","attack.t1021.002","attack.t1570","attack.execution","attack.t1569.002"],"path":"rules/windows/process_creation/proc_creation_win_rundll32_without_parameters.yml","techniques":["T1021.002","T1570","T1569.002"],"cves":[]},{"id":"61a7697c-cb79-42a8-a2ff-5f0cdfae0130","title":"Potential CobaltStrike Service Installations - Registry","author":"Wojciech Lesicki","status":"test","level":"high","date":"2021-06-29","modified":"2024-03-25","description":"Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement.\n","references":["https://www.sans.org/webcasts/tech-tuesday-workshop-cobalt-strike-detection-log-analysis-119395"],"logsource":{"product":"windows","category":"registry_set"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.lateral-movement","attack.t1021.002","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/registry/registry_set/registry_set_cobaltstrike_service_installs.yml","techniques":["T1021.002","T1543.003","T1569.002"],"cves":[]},{"id":"6fb63b40-e02a-403e-9ffd-3bcc1d749442","title":"Metasploit Or Impacket Service Installation Via SMB PsExec","author":"Bartlomiej Czyz, Relativity","status":"test","level":"high","date":"2021-01-21","modified":"2022-10-05","description":"Detects usage of Metasploit SMB PsExec (exploit/windows/smb/psexec) and Impacket psexec.py by triggering on specific service installation","references":["https://bczyz1.github.io/2021/01/30/psexec.html"],"logsource":{"product":"windows","service":"security"},"tags":["attack.lateral-movement","attack.t1021.002","attack.t1570","attack.execution","attack.t1569.002"],"path":"rules/windows/builtin/security/win_security_metasploit_or_impacket_smb_psexec_service_install.yml","techniques":["T1021.002","T1570","T1569.002"],"cves":[]},{"id":"771d1eb5-9587-4568-95fb-9ec44153a012","title":"PUA - NSudo Execution","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali","status":"test","level":"high","date":"2022-01-24","modified":"2023-02-13","description":"Detects the use of NSudo tool for command execution","references":["https://web.archive.org/web/20221019044836/https://nsudo.m2team.org/en-us/","https://www.winhelponline.com/blog/run-program-as-system-localsystem-account-windows/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1569.002","attack.s0029"],"path":"rules/windows/process_creation/proc_creation_win_pua_nsudo.yml","techniques":["T1569.002"],"cves":[]},{"id":"7eff1a7f-dd45-4c20-877a-f21e342a7611","title":"RemCom Service File Creation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-08-04","modified":null,"description":"Detects default RemCom service filename which indicates RemCom service installation and execution","references":["https://github.com/kavika13/RemCom/"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.execution","attack.t1569.002","attack.s0029"],"path":"rules/windows/file/file_event/file_event_win_remcom_service.yml","techniques":["T1569.002"],"cves":[]},{"id":"93199800-b52a-4dec-b762-75212c196542","title":"PUA - RunXCmd Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-01-24","modified":"2023-02-14","description":"Detects the use of the RunXCmd tool to execute commands with System or TrustedInstaller accounts","references":["https://www.d7xtech.com/free-software/runx/","https://www.winhelponline.com/blog/run-program-as-system-localsystem-account-windows/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1569.002","attack.s0029"],"path":"rules/windows/process_creation/proc_creation_win_pua_runxcmd.yml","techniques":["T1569.002"],"cves":[]},{"id":"97b9ce1e-c5ab-11ea-87d0-0242ac130003","title":"PSExec and WMI Process Creations Block","author":"Bhabesh Raj","status":"test","level":"high","date":"2020-07-14","modified":"2022-12-25","description":"Detects blocking of process creations originating from PSExec and WMI commands","references":["https://learn.microsoft.com/en-us/defender-endpoint/attack-surface-reduction-rules-reference?view=o365-worldwide#block-process-creations-originating-from-psexec-and-wmi-commands","https://twitter.com/duff22b/status/1280166329660497920"],"logsource":{"product":"windows","service":"windefend"},"tags":["attack.execution","attack.lateral-movement","attack.t1047","attack.t1569.002"],"path":"rules/windows/builtin/windefend/win_defender_asr_psexec_wmi.yml","techniques":["T1047","T1569.002"],"cves":[]},{"id":"9e36ed87-4986-482e-8e3b-5c23ffff11bf","title":"RemCom Service Installation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-08-07","modified":null,"description":"Detects RemCom service installation and execution events","references":["https://github.com/kavika13/RemCom/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.execution","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_remcom.yml","techniques":["T1569.002"],"cves":[]},{"id":"a27e5fa9-c35e-4e3d-b7e0-1ce2af66ad12","title":"CSExec Service Installation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-08-07","modified":null,"description":"Detects CSExec service installation and execution events","references":["https://github.com/malcomvetter/CSExec"],"logsource":{"product":"windows","service":"system"},"tags":["attack.execution","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_csexecsvc.yml","techniques":["T1569.002"],"cves":[]},{"id":"a2e5019d-a658-4c6a-92bf-7197b54e2cae","title":"PowerShell Scripts Installed as Services","author":"oscd.community, Natalia Shornikova","status":"test","level":"high","date":"2020-10-06","modified":"2022-12-25","description":"Detects powershell script installed as a Service","references":["https://speakerdeck.com/heirhabarov/hunting-for-powershell-abuse"],"logsource":{"product":"windows","service":"system"},"tags":["attack.execution","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_powershell_script_installed_as_service.yml","techniques":["T1569.002"],"cves":[]},{"id":"a7cd7306-df8b-4398-b711-6f3e4935cf16","title":"Potential CVE-2022-26809 Exploitation Attempt","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-04-13","modified":"2023-02-03","description":"Detects suspicious remote procedure call (RPC) service anomalies based on the spawned sub processes (long shot to detect the exploitation of vulnerabilities like CVE-2022-26809)","references":["https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-26809","https://www.bleepingcomputer.com/startups/RpcSs.exe-14544.html","https://twitter.com/cyb3rops/status/1514217991034097664","https://www.securonix.com/blog/cve-2022-26809-remote-procedure-call-runtime-remote-code-execution-vulnerability-and-coverage/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1190","attack.execution","attack.t1569.002","cve.2022-26809","detection.emerging-threats"],"path":"rules-emerging-threats/2022/Exploits/CVE-2022-26809/proc_creation_win_exploit_cve_2022_26809_rpcss_child_process_anomaly.yml","techniques":["T1190","T1569.002"],"cves":["CVE-2022-26809"]},{"id":"b5281f31-f9cc-4d0d-95d0-45b91c45b487","title":"DNS RCE CVE-2020-1350","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2020-07-15","modified":"2022-07-12","description":"Detects exploitation of DNS RCE bug reported in CVE-2020-1350 by the detection of suspicious sub process","references":["https://research.checkpoint.com/2020/resolving-your-way-into-domain-admin-exploiting-a-17-year-old-bug-in-windows-dns-servers/","https://web.archive.org/web/20230329172447/https://blog.menasec.net/2019/02/threat-hunting-24-microsoft-windows-dns.html"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.t1190","attack.execution","attack.t1569.002","cve.2020-1350","detection.emerging-threats"],"path":"rules-emerging-threats/2020/Exploits/CVE-2020-1350/proc_creation_win_exploit_cve_2020_1350.yml","techniques":["T1190","T1569.002"],"cves":["CVE-2020-1350"]},{"id":"b640c0b8-87f8-4daa-aef8-95a24261dd1d","title":"MITRE BZAR Indicators for Execution","author":"@neu5ron, SOC Prime","status":"test","level":"medium","date":"2020-03-19","modified":"2021-11-27","description":"Windows DCE-RPC functions which indicate an execution techniques on the remote system. All credit for the Zeek mapping of the suspicious endpoint/operation field goes to MITRE","references":["https://github.com/mitre-attack/bzar#indicators-for-attck-execution"],"logsource":{"product":"zeek","service":"dce_rpc"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.t1047","attack.t1053.002","attack.t1569.002"],"path":"rules/network/zeek/zeek_dce_rpc_mitre_bzar_execution.yml","techniques":["T1047","T1053.002","T1569.002"],"cves":[]},{"id":"bf74135c-18e8-4a72-a926-0e4f47888c19","title":"DNS Events Related To Mining Pools","author":"Saw Winn Naung, Azure-Sentinel, @neu5ron","status":"test","level":"low","date":"2021-08-19","modified":"2022-07-07","description":"Identifies clients that may be performing DNS lookups associated with common currency mining pools.","references":["https://github.com/Azure/Azure-Sentinel/blob/fa0411f9424b6c47b4d5a20165e4f1b168c1f103/Detections/ASimDNS/imDNS_Miners.yaml"],"logsource":{"product":"zeek","service":"dns"},"tags":["attack.execution","attack.t1569.002","attack.impact","attack.t1496"],"path":"rules/network/zeek/zeek_dns_mining_pools.yml","techniques":["T1569.002","T1496"],"cves":[]},{"id":"c484e533-ee16-4a93-b6ac-f0ea4868b2f1","title":"HackTool - SharpUp PrivEsc Tool Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2022-08-20","modified":"2023-02-13","description":"Detects the use of SharpUp, a tool for local privilege escalation","references":["https://github.com/GhostPack/SharpUp"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.discovery","attack.execution","attack.stealth","attack.t1615","attack.t1569.002","attack.t1574.005"],"path":"rules/windows/process_creation/proc_creation_win_hktl_sharpup.yml","techniques":["T1615","T1569.002","T1574.005"],"cves":[]},{"id":"c4ff1eac-84ad-44dd-a6fb-d56a92fc43a9","title":"ProcessHacker Privilege Elevation","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-05-27","modified":"2022-12-25","description":"Detects a ProcessHacker tool that elevated privileges to a very high level","references":["https://twitter.com/1kwpeter/status/1397816101455765504"],"logsource":{"product":"windows","service":"system"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_pua_proceshacker.yml","techniques":["T1543.003","T1569.002"],"cves":[]},{"id":"c8b00925-926c-47e3-beea-298fd563728e","title":"Remote Access Tool Services Have Been Installed - Security","author":"Connor Martin, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-12-23","modified":"2024-12-07","description":"Detects service installation of different remote access tools software. These software are often abused by threat actors to perform","references":["https://redcanary.com/blog/misbehaving-rats/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.persistence","attack.execution","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/security/win_security_service_install_remote_access_software.yml","techniques":["T1543.003","T1569.002"],"cves":[]},{"id":"cb062102-587e-4414-8efa-dbe3c7bf19c6","title":"CosmicDuke Service Installation","author":"Florian Roth (Nextron Systems), Daniil Yugoslavskiy, oscd.community (update)","status":"test","level":"critical","date":"2017-03-27","modified":"2022-10-09","description":"Detects the installation of a service named \"javamtsup\" on the system.\nThe CosmicDuke info stealer uses Windows services typically named \"javamtsup\" for persistence.\n","references":["https://blog.f-secure.com/wp-content/uploads/2019/10/CosmicDuke.pdf"],"logsource":{"product":"windows","service":"security"},"tags":["attack.privilege-escalation","attack.execution","attack.persistence","attack.t1543.003","attack.t1569.002","detection.emerging-threats"],"path":"rules-emerging-threats/2017/Malware/CosmicDuke/win_security_mal_cosmik_duke_persistence.yml","techniques":["T1543.003","T1569.002"],"cves":[]},{"id":"d08a2711-ee8b-4323-bdec-b7d85e892b31","title":"PUA - CsExec Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-08-22","modified":"2023-02-21","description":"Detects the use of the lesser known remote execution tool named CsExec a PsExec alternative","references":["https://github.com/malcomvetter/CSExec","https://www.microsoft.com/security/blog/2022/05/09/ransomware-as-a-service-understanding-the-cybercrime-gig-economy-and-how-to-protect-yourself/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.resource-development","attack.t1587.001","attack.execution","attack.t1569.002"],"path":"rules/windows/process_creation/proc_creation_win_pua_csexec.yml","techniques":["T1587.001","T1569.002"],"cves":[]},{"id":"d26ce60c-2151-403c-9a42-49420d87b5e4","title":"HackTool Service Registration or Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2022-03-21","modified":"2023-08-07","description":"Detects installation or execution of services","references":["Internal Research"],"logsource":{"product":"windows","service":"system"},"tags":["attack.execution","attack.t1569.002","attack.s0029"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_hacktools.yml","techniques":["T1569.002"],"cves":[]},{"id":"d36f87ea-c403-44d2-aa79-1a0ac7c24456","title":"PUA - RemCom Default Named Pipe","author":"Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-08-07","modified":"2023-11-30","description":"Detects default RemCom pipe creation","references":["https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view","https://github.com/kavika13/RemCom"],"logsource":{"product":"windows","category":"pipe_created"},"tags":["attack.lateral-movement","attack.t1021.002","attack.execution","attack.t1569.002"],"path":"rules/windows/pipe_created/pipe_created_pua_remcom_default_pipe.yml","techniques":["T1021.002","T1569.002"],"cves":[]},{"id":"d7a95147-145f-4678-b85d-d1ff4a3bb3f6","title":"CobaltStrike Service Installations - Security","author":"Florian Roth (Nextron Systems), Wojciech Lesicki","status":"test","level":"high","date":"2021-05-26","modified":"2022-11-27","description":"Detects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement","references":["https://www.sans.org/webcasts/119395","https://www.crowdstrike.com/blog/getting-the-bacon-from-cobalt-strike-beacon/","https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.execution","attack.privilege-escalation","attack.lateral-movement","attack.t1021.002","attack.t1543.003","attack.t1569.002"],"path":"rules/windows/builtin/security/win_security_cobaltstrike_service_installs.yml","techniques":["T1021.002","T1543.003","T1569.002"],"cves":[]},{"id":"d9047477-0359-48c9-b8c7-792cedcdc9c4","title":"PUA - NirCmd Execution As LOCAL SYSTEM","author":"Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-01-24","modified":"2023-02-13","description":"Detects the use of NirCmd tool for command execution as SYSTEM user","references":["https://www.nirsoft.net/utils/nircmd.html","https://www.winhelponline.com/blog/run-program-as-system-localsystem-account-windows/","https://www.nirsoft.net/utils/nircmd2.html#using"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.t1569.002","attack.s0029"],"path":"rules/windows/process_creation/proc_creation_win_pua_nircmd_as_system.yml","techniques":["T1569.002"],"cves":[]},{"id":"de7ce410-b3fb-4e8a-b38c-3b999e2c3420","title":"PAExec Service Installation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-10-26","modified":null,"description":"Detects PAExec service installation","references":["https://www.poweradmin.com/paexec/"],"logsource":{"product":"windows","service":"system"},"tags":["attack.execution","attack.t1569.002"],"path":"rules/windows/builtin/system/service_control_manager/win_system_service_install_paexec.yml","techniques":["T1569.002"],"cves":[]},{"id":"f0d1feba-4344-4ca9-8121-a6c97bd6df52","title":"Credential Dumping Tools Service Execution - Security","author":"Florian Roth (Nextron Systems), Teymur Kheirkhabarov, Daniil Yugoslavskiy, oscd.community","status":"test","level":"high","date":"2017-03-05","modified":"2022-11-29","description":"Detects well-known credential dumping tools execution via service execution events","references":["https://www.slideshare.net/heirhabarov/hunting-for-credentials-dumping-in-windows-environment"],"logsource":{"product":"windows","service":"security"},"tags":["attack.credential-access","attack.execution","attack.t1003.001","attack.t1003.002","attack.t1003.004","attack.t1003.005","attack.t1003.006","attack.t1569.002","attack.s0005"],"path":"rules/windows/builtin/security/win_security_mal_creddumper.yml","techniques":["T1003.001","T1003.002","T1003.004","T1003.005","T1003.006","T1569.002"],"cves":[]},{"id":"f0e2b768-5220-47dd-b891-d57b96fc0ec1","title":"CSExec Service File Creation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-08-04","modified":null,"description":"Detects default CSExec service filename which indicates CSExec service installation and execution","references":["https://github.com/malcomvetter/CSExec"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.execution","attack.t1569.002","attack.s0029"],"path":"rules/windows/file/file_event/file_event_win_csexec_service.yml","techniques":["T1569.002"],"cves":[]},{"id":"f318b911-ea88-43f4-9281-0de23ede628e","title":"PUA - CSExec Default Named Pipe","author":"Nikita Nazarov, oscd.community, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2023-08-07","modified":"2023-11-30","description":"Detects default CSExec pipe creation","references":["https://drive.google.com/file/d/1lKya3_mLnR3UQuCoiYruO3qgu052_iS_/view","https://github.com/malcomvetter/CSExec"],"logsource":{"product":"windows","category":"pipe_created"},"tags":["attack.lateral-movement","attack.t1021.002","attack.execution","attack.t1569.002"],"path":"rules/windows/pipe_created/pipe_created_pua_csexec_default_pipe.yml","techniques":["T1021.002","T1569.002"],"cves":[]},{"id":"f3f3a972-f982-40ad-b63c-bca6afdfad7c","title":"PsExec Default Named Pipe","author":"Thomas Patzke","status":"test","level":"low","date":"2017-06-12","modified":"2022-10-09","description":"Detects PsExec service default pipe creation","references":["https://www.jpcert.or.jp/english/pub/sr/ir_research.html","https://jpcertcc.github.io/ToolAnalysisResultSheet"],"logsource":{"product":"windows","category":"pipe_created"},"tags":["attack.execution","attack.t1569.002","attack.s0029","detection.threat-hunting"],"path":"rules-threat-hunting/windows/pipe_created/pipe_created_sysinternals_psexec_default_pipe.yml","techniques":["T1569.002"],"cves":[]},{"id":"f6451de4-df0a-41fa-8d72-b39f54a08db5","title":"PUA - PAExec Default Named Pipe","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-10-26","modified":null,"description":"Detects PAExec default named pipe","references":["https://github.com/microsoft/Microsoft-365-Defender-Hunting-Queries/blob/efa17a600b43c897b4b7463cc8541daa1987eeb4/Command%20and%20Control/C2-NamedPipe.md","https://github.com/poweradminllc/PAExec"],"logsource":{"product":"windows","category":"pipe_created"},"tags":["attack.execution","attack.t1569.002"],"path":"rules/windows/pipe_created/pipe_created_pua_paexec_default_pipe.yml","techniques":["T1569.002"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2021-35394","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}