Elastic medium stable eql
System Shells via Services
Windows services typically run as SYSTEM and can be used as a privilege escalation opportunity. Malware or penetration testers may run a shell as a service to gain SYSTEM permissions.
Detection Logic
process where host.os.type == "windows" and event.type == "start" and
process.parent.name : "services.exe" and
process.name : ("cmd.exe", "powershell.exe", "pwsh.exe", "powershell_ise.exe") and
/* Third party FP's */
not process.args : "NVDisplay.ContainerLocalSystem" Field Validations
Loading…
Comments (0)
Loading comments...