MITRE ATT&CK technique
System Services detection rulesT1569
System Services (T1569) is a MITRE ATT&CK technique in the Execution tactic. This page lists the 48 community-maintained Sigma detection rules in the library mapped to T1569 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target windows, zeek, rpc_firewall.
Top products
Tactic
CobaltStrike Service Installations - System
criticalDetects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement
windows
CosmicDuke Service Installation
criticalDetects the installation of a service named "javamtsup" on the system. The CosmicDuke info stealer uses Windows services typically named "javamtsup" for persistence.
windows
CVE-2021-1675 Print Spooler Exploitation
criticalDetects driver load events print service operational log that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675
windows
CVE-2021-1675 Print Spooler Exploitation IPC Access
criticalDetects remote printer driver load from Detailed File Share in Security logs that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675 and CVE-2021-34527
windows
DNS RCE CVE-2020-1350
criticalDetects exploitation of DNS RCE bug reported in CVE-2020-1350 by the detection of suspicious sub process
windows · process_creation
HackTool - SharpUp PrivEsc Tool Execution
criticalDetects the use of SharpUp, a tool for local privilege escalation
windows · process_creation
CobaltStrike Service Installations - Security
highDetects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement
windows
Credential Dumping Tools Service Execution - Security
highDetects well-known credential dumping tools execution via service execution events
windows
Credential Dumping Tools Service Execution - System
highDetects well-known credential dumping tools execution via service execution events
windows
HackTool Service Registration or Execution
highDetects installation or execution of services
windows
Metasploit Or Impacket Service Installation Via SMB PsExec
highDetects usage of Metasploit SMB PsExec (exploit/windows/smb/psexec) and Impacket psexec.py by triggering on specific service installation
windows
Possible CVE-2021-1675 Print Spooler Exploitation
highDetects events of driver load errors in print service logs that could be a sign of successful exploitation attempts of print spooler vulnerability CVE-2021-1675
windows
Potential CobaltStrike Service Installations - Registry
highDetects known malicious service installs that appear in cases in which a Cobalt Strike beacon elevates privileges or lateral movement.
windows · registry_set
Potential CVE-2022-26809 Exploitation Attempt
highDetects suspicious remote procedure call (RPC) service anomalies based on the spawned sub processes (long shot to detect the exploitation of vulnerabilities like CVE-2022-26809)
windows · process_creation
PowerShell as a Service in Registry
highDetects that a powershell code is written to the registry as a service.
windows · registry_set
PowerShell Scripts Installed as Services
highDetects powershell script installed as a Service
windows
PowerShell Scripts Installed as Services - Security
highDetects powershell script installed as a Service
windows
ProcessHacker Privilege Elevation
highDetects a ProcessHacker tool that elevated privileges to a very high level
windows
PSExec and WMI Process Creations Block
highDetects blocking of process creations originating from PSExec and WMI commands
windows
PUA - CsExec Execution
highDetects the use of the lesser known remote execution tool named CsExec a PsExec alternative
windows · process_creation
PUA - NirCmd Execution As LOCAL SYSTEM
highDetects the use of NirCmd tool for command execution as SYSTEM user
windows · process_creation
PUA - NSudo Execution
highDetects the use of NSudo tool for command execution
windows · process_creation
PUA - RunXCmd Execution
highDetects the use of the RunXCmd tool to execute commands with System or TrustedInstaller accounts
windows · process_creation
Remote Server Service Abuse for Lateral Movement
highDetects remote RPC calls to possibly abuse remote encryption service via MS-EFSR
rpc_firewall · application
Rundll32 Execution Without Parameters
highDetects rundll32 execution without parameters as observed when running Metasploit windows/smb/psexec exploit module
windows · process_creation
Sliver C2 Default Service Installation
highDetects known malicious service installation that appear in cases in which a Sliver implants execute the PsExec commands
windows
smbexec.py Service Installation
highDetects the use of smbexec.py tool by detecting a specific service installation
windows
CSExec Service File Creation
mediumDetects default CSExec service filename which indicates CSExec service installation and execution
windows · file_event
CSExec Service Installation
mediumDetects CSExec service installation and execution events
windows
Launch Agent/Daemon Execution Via Launchctl
mediumDetects the execution of programs as Launch Agents or Launch Daemons using launchctl on macOS.
macos · process_creation
MITRE BZAR Indicators for Execution
mediumWindows DCE-RPC functions which indicate an execution techniques on the remote system. All credit for the Zeek mapping of the suspicious endpoint/operation field goes to MITRE
zeek
PAExec Service Installation
mediumDetects PAExec service installation
windows
Psexec Execution
mediumDetects user accept agreement execution in psexec commandline
windows · process_creation
PsExec Service Installation
mediumDetects PsExec service installation and execution events
windows
PsExec Tool Execution From Suspicious Locations - PipeName
mediumDetects PsExec default pipe creation where the image executed is located in a suspicious location. Which could indicate that the tool is being used in an attack
windows · pipe_created
PUA - CSExec Default Named Pipe
mediumDetects default CSExec pipe creation
windows · pipe_created
PUA - NirCmd Execution
mediumDetects the use of NirCmd tool for command execution, which could be the result of legitimate administrative activity
windows · process_creation
PUA - PAExec Default Named Pipe
mediumDetects PAExec default named pipe
windows · pipe_created
PUA - RemCom Default Named Pipe
mediumDetects default RemCom pipe creation
windows · pipe_created
RemCom Service File Creation
mediumDetects default RemCom service filename which indicates RemCom service installation and execution
windows · file_event
RemCom Service Installation
mediumDetects RemCom service installation and execution events
windows
Remote Access Tool Services Have Been Installed - Security
mediumDetects service installation of different remote access tools software. These software are often abused by threat actors to perform
windows
Remote Access Tool Services Have Been Installed - System
mediumDetects service installation of different remote access tools software. These software are often abused by threat actors to perform
windows
WFP Filter Added via Registry
mediumDetects registry modifications that add Windows Filtering Platform (WFP) filters, which may be used to block security tools and EDR agents from reporting events.
windows · registry_set
DNS Events Related To Mining Pools
lowIdentifies clients that may be performing DNS lookups associated with common currency mining pools.
zeek
PsExec Default Named Pipe
lowDetects PsExec service default pipe creation
windows · pipe_created
PsExec Service File Creation
lowDetects default PsExec service filename which indicates PsExec service installation and execution
windows · file_event
Start Windows Service Via Net.EXE
lowDetects the usage of the "net.exe" command to start a service using the "start" flag
windows · process_creation