Technique with 3 sub-techniques.View on attack.mitre.org
Adversaries may abuse system services or daemons to execute commands or programs. Adversaries can execute malicious content by interacting with or creating services either locally or remotely. Many services are set to run at boot, which can aid in achieving persistence (Create or Modify System Process), but adversaries can also abuse services for one-time or temporary execution.
Rules on DetectionCode tagged with T1569 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Detect Renamed PSExec | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1569.002 |
| Excessive Usage Of SC Service Utility | Anomaly | NULL | Sysmon EventID 1 | T1569.002 |
| First Time Seen Running Windows Service | Anomaly | NULL | Windows Event Log System 7036 | T1569.002 |
| Linux Auditd Service Started | Anomaly | NULL | Linux Auditd Proctitle | T1569.002 |
| Malicious Powershell Executed As A Service | TTP | NULL | Windows Event Log System 7045 | T1569.002 |
| Windows ScManager Security Descriptor Tampering Via Sc.EXE | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1569.002 |
| Windows Service Create SliverC2 | TTP | NULL | Windows Event Log System 7045 | T1569.002 |
| Windows Service Created with Suspicious Service Name | Anomaly | NULL | Windows Event Log System 7045 | T1569.002 |
| Windows Service Created with Suspicious Service Path | TTP | NULL | Windows Event Log System 7045 | T1569.002 |
| Windows Service Execution RemCom | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1569.002 |
| Windows Snake Malware Service Create | TTP | NULL | Windows Event Log System 7045 | T1569.002 |
None recorded.
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.