Interesting Service Enumeration Via Sc.EXE

 Original Source: [Sigma source]
Title: Interesting Service Enumeration Via Sc.EXE
Status: test
Description:Detects the enumeration and query of interesting and in some cases sensitive services on the system via "sc.exe". Attackers often try to enumerate the services currently running on a system in order to find different attack vectors.
References:
  -https://www.n00py.io/2021/05/dumping-plaintext-rdp-credentials-from-svchost-exe/
  -https://pentestlab.blog/tag/svchost/
Author: Swachchhanda Shrawan Poudel
Date: 2024-02-12
modified:None
Tags:
  • -'attack.t1003'
  • -'attack.credential-access'
Logsource:
  • product: windows
  • category: process_creation
Detection:
  selection_img:
Image|endswith:'\sc.exe' OriginalFileName:'sc.exe'   selection_cli:
    CommandLine|contains: 'query'
  selection_cmd:
    CommandLine|contains: 'termservice'
  condition:all of selection_*
Falsepositives:
  -Unknown
Level: low