Elastic medium stable eql
Remote Windows Service Installed
Identifies a network logon followed by Windows service creation with same LogonId. This could be indicative of lateral movement, but will be noisy if commonly done by administrators."
Detection Logic
sequence by winlog.logon.id, winlog.computer_name with maxspan=1m
[authentication where host.os.type == "windows" and event.action == "logged-in" and winlog.logon.type : "Network" and
event.outcome == "success" and source.ip != null and source.ip != "127.0.0.1" and source.ip != "::1"]
[iam where host.os.type == "windows" and event.action == "service-installed" and
not winlog.event_data.SubjectLogonId : "0x3e7" and
not winlog.event_data.ServiceFileName :
("?:\\Windows\\ADCR_Agent\\adcrsvc.exe",
"?:\\Windows\\System32\\VSSVC.exe",
"?:\\Windows\\servicing\\TrustedInstaller.exe",
"?:\\Windows\\System32\\svchost.exe",
"?:\\Program Files (x86)\\*.exe",
"?:\\Program Files\\*.exe",
"?:\\Windows\\PSEXESVC.EXE",
"?:\\Windows\\System32\\sppsvc.exe",
"?:\\Windows\\System32\\wbem\\WmiApSrv.exe",
"?:\\WINDOWS\\RemoteAuditService.exe",
"?:\\Windows\\VeeamVssSupport\\VeeamGuestHelper.exe",
"?:\\Windows\\VeeamLogShipper\\VeeamLogShipper.exe",
"?:\\Windows\\CAInvokerService.exe",
"?:\\Windows\\System32\\upfc.exe",
"?:\\Windows\\AdminArsenal\\PDQ*.exe",
"?:\\Windows\\System32\\vds.exe",
"?:\\Windows\\Veeam\\Backup\\VeeamDeploymentSvc.exe",
"?:\\Windows\\ProPatches\\Scheduler\\STSchedEx.exe",
"?:\\Windows\\System32\\certsrv.exe",
"?:\\Windows\\eset-remote-install-service.exe",
"?:\\Pella Corporation\\Pella Order Management\\GPAutoSvc.exe",
"?:\\Pella Corporation\\OSCToGPAutoService\\OSCToGPAutoSvc.exe",
"?:\\Pella Corporation\\Pella Order Management\\GPAutoSvc.exe",
"?:\\Windows\\SysWOW64\\NwxExeSvc\\NwxExeSvc.exe",
"?:\\Windows\\System32\\taskhostex.exe")] Field Validations
Loading…
Comments (0)
Loading comments...