Potential Persistence Attempt Via Existing Service Tampering

 Original Source: [Sigma source]
Title: Potential Persistence Attempt Via Existing Service Tampering
Status: test
Description:Detects the modification of an existing service in order to execute an arbitrary payload when the service is started or killed as a potential method for persistence.
References:
  -https://pentestlab.blog/2020/01/22/persistence-modify-existing-service/
Author: Sreeman
Date: 2020-09-29
modified:2023-02-04
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1543.003'
  • -'attack.t1574.011'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_sc:
    - CommandLine|contains|all:
      - 'sc '
      - 'config '
      - 'binpath='
    - CommandLine|contains|all:
      - 'sc '
      - 'failure'
      - 'command='
  selection_reg_img:
    - CommandLine|contains|all:
      - 'reg '
      - 'add '
      - 'FailureCommand'
    - CommandLine|contains|all:
      - 'reg '
      - 'add '
      - 'ImagePath'
  selection_reg_ext:
    CommandLine|contains:
      -'.sh'
      -'.exe'
      -'.dll'
      -'.bin$'
      -'.bat'
      -'.cmd'
      -'.js'
      -'.msh$'
      -'.reg$'
      -'.scr'
      -'.ps'
      -'.vb'
      -'.jar'
      -'.pl'

  condition:selection_sc or all of selection_reg_*
Falsepositives:
  -Unknown
Level: medium