Uncommon Service Installation Image Path

 Original Source: [Sigma source]
Title: Uncommon Service Installation Image Path
Status: test
Description:Detects uncommon service installation commands by looking at suspicious or uncommon image path values containing references to encoded powershell commands, temporary paths, etc.
References:
  -Internal Research
Author: Florian Roth (Nextron Systems)
Date: 2022-03-18
modified:2024-02-09
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'car.2013-09-005'
  • -'attack.t1543.003'
Logsource:
  • product: windows
  • service: system
Detection:
  selection:
    Provider_Name: 'Service Control Manager'
    EventID: '7045'
  suspicious_paths:
    ImagePath|contains:
      -'\\\\.\\pipe'
      -'\Users\Public\'
      -'\Windows\Temp\'

  suspicious_encoded_flag:
    ImagePath|contains: ' -e'
  suspicious_encoded_keywords:
    ImagePath|contains:
      -' aQBlAHgA'
      -' aWV4I'
      -' IAB'
      -' JAB'
      -' PAA'
      -' SQBFAFgA'
      -' SUVYI'

  filter_optional_thor_remote:
    ImagePath|startswith: 'C:\WINDOWS\TEMP\thor10-remote\thor64.exe'
  filter_main_defender_def_updates:
    ImagePath|startswith: 'C:\ProgramData\Microsoft\Windows Defender\Definition Updates\'
  condition:selection and ( suspicious_paths or all of suspicious_encoded_* ) and not 1 of filter_main_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: medium