Service Installation with Suspicious Folder Pattern

 Original Source: [Sigma source]
Title: Service Installation with Suspicious Folder Pattern
Status: test
Description:Detects service installation with suspicious folder patterns
References:
  -Internal Research
Author: pH-T (Nextron Systems)
Date: 2022-03-18
modified:2022-03-24
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'car.2013-09-005'
  • -'attack.t1543.003'
Logsource:
  • product: windows
  • service: system
Detection:
  selection_eid:
    Provider_Name: 'Service Control Manager'
    EventID: '7045'
  selection_img_paths:
ImagePath|re:'^[Cc]:\\[Pp]rogram[Dd]ata\\.{1,9}\.exe' ImagePath|re:'^[Cc]:\\.{1,9}\.exe'   condition:all of selection_*
Falsepositives:
  -Unknown
Level: high