Sigma medium test sigma

Uncommon Service Installation Image Path

Detects uncommon service installation commands by looking at suspicious or uncommon image path values containing references to encoded powershell commands, temporary paths, etc.

View Source

Detection Logic

{
  "selection": {
    "Provider_Name": "Service Control Manager",
    "EventID": 7045
  },
  "suspicious_paths": {
    "ImagePath
| contains": [
      "\\\\\\\\.\\\\pipe",
      "\\Users\\Public\\",
      "\\Windows\\Temp\\"
    ]
  },
  "suspicious_encoded_flag": {
    "ImagePath
| contains": " -e"
  },
  "suspicious_encoded_keywords": {
    "ImagePath
| contains": [
      " aQBlAHgA",
      " aWV4I",
      " IAB",
      " JAB",
      " PAA",
      " SQBFAFgA",
      " SUVYI"
    ]
  },
  "filter_optional_thor_remote": {
    "ImagePath
| startswith": "C:\\WINDOWS\\TEMP\\thor10-remote\\thor64.exe"
  },
  "filter_main_defender_def_updates": {
    "ImagePath
| startswith": "C:\\ProgramData\\Microsoft\\Windows Defender\\Definition Updates\\"
  },
  "condition": "selection and ( suspicious_paths or all of suspicious_encoded_* ) and not 1 of filter_main_* and not 1 of filter_optional_*"
}

False Positives

  • Unknown

Field Validations

Loading…

Comments (0)

Loading comments...