Suspicious Service Installed

 Original Source: [Sigma source]
Title: Suspicious Service Installed
Status: test
Description:Detects installation of NalDrv or PROCEXP152 services via registry-keys to non-system32 folders. Both services are used in the tool Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU (https://github.com/hfiref0x/KDU)
References:
  -https://web.archive.org/web/20200419024230/https://blog.dylan.codes/evading-sysmon-and-windows-event-logging/
Author: xknow (@xknow_infosec), xorxes (@xor_xes)
Date: 2019-04-08
modified:2026-06-29
Tags:
  • -'attack.defense-impairment'
  • -'attack.t1685'
Logsource:
  • category: registry_set
  • product: windows
Detection:
  selection:
    TargetObject:
      -'HKLM\System\CurrentControlSet\Services\NalDrv\ImagePath'
      -'HKLM\System\CurrentControlSet\Services\PROCEXP152\ImagePath'

  filter:
    Image|endswith:
      -'\procexp64.exe'
      -'\procexp64a.exe'
      -'\procexp.exe'
      -'\procmon64.exe'
      -'\procmon64a.exe'
      -'\procmon.exe'
      -'\handle.exe'
      -'\handle64.exe'
      -'\handle64a.exe'

    Details|contains: '\WINDOWS\system32\Drivers\PROCEXP152.SYS'
  condition:selection and not filter
Falsepositives:
  -Other legimate tools using this service names and drivers. Note - clever attackers may easily bypass this detection by just renaming the services. Therefore just Medium-level and don't rely on it.
Level: medium