This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
Possible Privilege Escalation via Weak Service Permissions
Original Source:
[Sigma source]
Title:
Possible Privilege Escalation via Weak Service Permissions
Status:
test
Description:
Detection of sc.exe utility spawning by user with Medium integrity level to change service ImagePath or FailureCommand
References:
-https://speakerdeck.com/heirhabarov/hunting-for-privilege-escalation-in-windows-environment
-https://pentestlab.blog/2017/03/30/weak-service-permissions/
Author:
Teymur Kheirkhabarov
Date:
2019-10-26
modified:
2024-12-01
Tags:
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.execution'
-'attack.stealth'
-'attack.t1574.011'
Logsource:
category: process_creation
product: windows
Detection:
scbynonadmin:
Image|endswith
:
'\sc.exe'
IntegrityLevel
:
-'Medium'
-'S-1-16-8192'
selection_binpath:
CommandLine|contains|all
:
-'config'
-'binPath'
selection_failure:
CommandLine|contains|all
:
-'failure'
-'command'
condition
:
scbynonadmin and 1 of selection_*
Falsepositives:
-Unknown
Level:
high