Possible Privilege Escalation via Weak Service Permissions
Detection of sc.exe utility spawning by user with Medium integrity level to change service ImagePath or FailureCommand
Detection logic
scbynonadmin
Image|endswith: \sc.exe
IntegrityLevel:
- Medium
- S-1-16-8192selection_binpath
CommandLine|contains|all:
- config
- binPathselection_failure
CommandLine|contains|all:
- failure
- commandCondition
scbynonadmin and 1 of selection_*Raw YAML
title: Possible Privilege Escalation via Weak Service Permissions
id: d937b75f-a665-4480-88a5-2f20e9f9b22a
status: test
description: Detection of sc.exe utility spawning by user with Medium integrity level to change service ImagePath or FailureCommand
references:
- https://speakerdeck.com/heirhabarov/hunting-for-privilege-escalation-in-windows-environment
- https://pentestlab.blog/2017/03/30/weak-service-permissions/
author: Teymur Kheirkhabarov
date: 2019-10-26
modified: 2024-12-01
tags:
- attack.persistence
- attack.privilege-escalation
- attack.execution
- attack.stealth
- attack.t1574.011
logsource:
category: process_creation
product: windows
detection:
scbynonadmin:
Image|endswith: '\sc.exe'
IntegrityLevel:
- 'Medium'
- 'S-1-16-8192'
selection_binpath:
CommandLine|contains|all:
- 'config'
- 'binPath'
selection_failure:
CommandLine|contains|all:
- 'failure'
- 'command'
condition: scbynonadmin and 1 of selection_*
falsepositives:
- Unknown
level: highFalse positives
- Unknown
References
Similar rules
Abuse of Service Permissions to Hide Services Via Set-Service
highwindows · Shares T1574
Changing Existing Service ImagePath Value Via Reg.EXE
mediumwindows · Shares T1574
Potential Persistence Attempt Via Existing Service Tampering
mediumwindows · Shares T1574
Potential Privilege Escalation via Service Permissions Weakness
highwindows · Shares T1574