This website uses cookies to ensure you get the best experience.
Got it!
Register
|
Login
Menu
Home
Sigma Rules
Splunk Rules
Explore Rules
Analytic Stories
MITRE ATT&CK
Overview
Matrix
Techniques
Groups
Software
Campaigns
Search
About
ServiceDll Hijack
Original Source:
[Sigma source]
Title:
ServiceDll Hijack
Status:
test
Description:
Detects changes to the "ServiceDLL" value related to a service in the registry. This is often used as a method of persistence.
References:
-https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1543.003/T1543.003.md#atomic-test-4---tinyturla-backdoor-service-w64time
-https://www.hexacorn.com/blog/2013/09/19/beyond-good-ol-run-key-part-4/
Author:
frack113
Date:
2022-02-04
modified:
2026-08-31
Tags:
-'attack.persistence'
-'attack.privilege-escalation'
-'attack.t1543.003'
Logsource:
category: registry_set
product: windows
Detection:
selection:
TargetObject|contains|all
:
-'\System\'
-'ControlSet'
-'\Services\'
TargetObject|endswith
:
'\Parameters\ServiceDll'
filter_main_printextensionmanger_1:
Details
:
'C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll'
filter_main_printextensionmanger_2:
Image|endswith
:
'\regsvr32.exe'
TargetObject|endswith
:
'\Services\PrintNotify\Parameters\ServiceDll'
Details|startswith
:
'C:\WINDOWS\System32\DriverStore\FileRepository\'
Details|endswith
:
'\arm64\PrintConfig.dll'
filter_main_domain_controller:
Image
:
'C:\Windows\system32\lsass.exe'
TargetObject|endswith
:
'\Services\NTDS\Parameters\ServiceDll'
Details
:
'%%systemroot%%\system32\ntdsa.dll'
filter_main_poqexec:
Image
:
'C:\Windows\System32\poqexec.exe'
filter_optional_safetica:
Image|endswith
:
'\regsvr32.exe'
Details
:
'C:\Windows\System32\STAgent.dll'
condition
:
selection and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
-Administrative scripts
-Installation of a service
Level:
medium