Suspicious Service DACL Modification Via Set-Service Cmdlet

 Original Source: [Sigma source]
Title: Suspicious Service DACL Modification Via Set-Service Cmdlet
Status: test
Description:Detects suspicious DACL modifications via the "Set-Service" cmdlet using the "SecurityDescriptorSddl" flag (Only available with PowerShell 7) that can be used to hide services or make them unstopable
References:
  -https://www.sans.org/blog/red-team-tactics-hiding-windows-services/
  -https://learn.microsoft.com/pt-br/windows/win32/secauthz/sid-strings
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-10-18
modified:None
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1543.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\pwsh.exe' OriginalFileName:'pwsh.dll'   selection_sddl_flag:
    CommandLine|contains:
      -'-SecurityDescriptorSddl '
      -'-sd '

  selection_set_service:
    CommandLine|contains|all:
      -'Set-Service '
      -'D;;'

    CommandLine|contains:
      -';;;IU'
      -';;;SU'
      -';;;BA'
      -';;;SY'
      -';;;WD'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: high