Sagan critical stable other

[WINDOWS-SECURITY] Suspicious Service Control Command

[WINDOWS-SECURITY] Suspicious Service Control Command

View Source

Detection Logic

alert any $HOME_NET any -> $HOME_NET any (msg:"[WINDOWS-SECURITY] Suspicious Service Control Command"; program:*Security*
| *Sysmon*; event_id:1,4688; content:"sc create"; nocase; content:"binPath="; nocase; reference:url,https://attack.mitre.org/techniques/T1543/003/; classtype:trojan-activity; sid:5014329; rev:1; metadata:deployment Server,affected_product NONE,affected_version NONE,mitigation NONE,deprecation_reason NONE,tag NONE, created_at 2024_02_28, updated_at 2024_02_28, mitre_tactic_id TA0003, mitre_technique_id T1543.003;)

Field Validations

Loading…

Comments (0)

Loading comments...