Service Binary in Suspicious Folder

 Original Source: [Sigma source]
Title: Service Binary in Suspicious Folder
Status: test
Description:Detect the creation of a service with a service binary located in a suspicious directory
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1562.001/T1562.001.md
Author: Florian Roth (Nextron Systems), frack113
Date: 2022-05-02
modified:2025-10-07
Tags:
  • -'attack.persistence'
  • -'attack.defense-impairment'
  • -'attack.t1112'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection_service_start:
    TargetObject|startswith: 'HKLM\System\CurrentControlSet\Services\'
    TargetObject|endswith: '\Start'
    Image|contains:
      -'\Users\Public\'
      -'\Perflogs\'
      -'\ADMIN$\'
      -'\Temp\'

    Details:
      -'DWORD (0x00000000)'
      -'DWORD (0x00000001)'
      -'DWORD (0x00000002)'

  selection_service_imagepath:
    TargetObject|startswith: 'HKLM\System\CurrentControlSet\Services\'
    TargetObject|endswith: '\ImagePath'
    Details|contains:
      -'\Users\Public\'
      -'\Perflogs\'
      -'\ADMIN$\'
      -'\Temp\'

  filter_optional_avast:
    Image|contains|all:
      -'\Common Files\'
      -'\Temp\'

  filter_optional_mbamservice:
    TargetObject|endswith: '\CurrentControlSet\Services\MBAMInstallerService\ImagePath'
    Details|endswith: '\AppData\Local\Temp\MBAMInstallerService.exe"'
    Image: 'C:\Windows\system32\services.exe'
  condition:1 of selection_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: high