Title:
Suspicious Service Installed
Status:
test
Description:Detects installation of NalDrv or PROCEXP152 services via registry-keys to non-system32 folders.
Both services are used in the tool Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU (https://github.com/hfiref0x/KDU)
References:
-https://web.archive.org/web/20200419024230/https://blog.dylan.codes/evading-sysmon-and-windows-event-logging/
Author: xknow (@xknow_infosec), xorxes (@xor_xes)
Date: 2019-04-08
modified:2026-06-29
Tags:
- -'attack.defense-impairment'
- -'attack.t1685'
Logsource:
- category: registry_set
- product: windows
Detection:
selection:
TargetObject:
-'HKLM\System\CurrentControlSet\Services\NalDrv\ImagePath'
-'HKLM\System\CurrentControlSet\Services\PROCEXP152\ImagePath'
filter:
Image|endswith:
-'\procexp64.exe'
-'\procexp64a.exe'
-'\procexp.exe'
-'\procmon64.exe'
-'\procmon64a.exe'
-'\procmon.exe'
-'\handle.exe'
-'\handle64.exe'
-'\handle64a.exe'
Details|contains:
'\WINDOWS\system32\Drivers\PROCEXP152.SYS'
condition:
selection and not filter
Falsepositives:
-Other legimate tools using this service names and drivers. Note - clever attackers may easily bypass this detection by just renaming the services. Therefore just Medium-level and don't rely on it.
Level:
medium