1200KM / detection
T1543.003 Windows Service — Detection Rules
Detection workspace for T1543.003 Windows Service: 38 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Special File Creation via Mknod Syscall · experimental · low · {"product":"linux","service":"auditd"}
- CobaltStrike Service Installations - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Remote Access Tool Services Have Been Installed - Security · test · medium · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- CobaltStrike Service Installations - System · test · critical · {"product":"windows","service":"system"}
- Moriya Rootkit - System · test · critical · {"product":"windows","service":"system"}
- New PDQDeploy Service - Server Side · test · medium · {"product":"windows","service":"system"}
- New PDQDeploy Service - Client Side · test · medium · {"product":"windows","service":"system"}
- ProcessHacker Privilege Elevation · test · high · {"product":"windows","service":"system"}
- Remote Access Tool Services Have Been Installed - System · test · medium · {"product":"windows","service":"system"}
- Sliver C2 Default Service Installation · test · high · {"product":"windows","service":"system"}
- Suspicious Service Installation · test · high · {"product":"windows","service":"system"}
- Uncommon Service Installation Image Path · test · medium · {"product":"windows","service":"system"}
- Service Installation in Suspicious Folder · test · medium · {"product":"windows","service":"system"}
- Service Installation with Suspicious Folder Pattern · test · high · {"product":"windows","service":"system"}
- Suspicious Service Installation Script · test · high · {"product":"windows","service":"system"}
- Malicious Driver Load · test · high · {"product":"windows","category":"driver_load"}
- Malicious Driver Load By Name · test · medium · {"product":"windows","category":"driver_load"}
- Driver Load From A Temporary Directory · test · high · {"category":"driver_load","product":"windows"}
- Vulnerable Driver Load · test · high · {"product":"windows","category":"driver_load"}
- Vulnerable Driver Load By Name · test · low · {"product":"windows","category":"driver_load"}
- Vulnerable HackSys Extreme Vulnerable Driver Load · test · high · {"product":"windows","category":"driver_load"}
- Vulnerable WinRing0 Driver Load · test · high · {"product":"windows","category":"driver_load"}
- PSEXEC Remote Execution File Artefact · test · high · {"category":"file_event","product":"windows"}
- Devcon Execution Disabling VMware VMCI Device · experimental · high · {"category":"process_creation","product":"windows"}
- New Service Creation Using PowerShell · test · low · {"category":"process_creation","product":"windows"}
- Suspicious Service DACL Modification Via Set-Service Cmdlet · test · high · {"category":"process_creation","product":"windows"}
- PUA - Kernel Driver Utility (KDU) Execution · experimental · high · {"category":"process_creation","product":"windows"}
- New Service Creation Using Sc.EXE · test · low · {"category":"process_creation","product":"windows"}
- New Kernel Driver Via SC.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Allow Service Access Using Security Descriptor Tampering Via Sc.EXE · test · high · {"category":"process_creation","product":"windows"}
- Deny Service Access Using Security Descriptor Tampering Via Sc.EXE · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Service Path Modification · test · high · {"category":"process_creation","product":"windows"}
- Potential Persistence Attempt Via Existing Service Tampering · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious New Service Creation · test · high · {"category":"process_creation","product":"windows"}
- Sysinternals PsService Execution · test · medium · {"category":"process_creation","product":"windows"}
- Sysinternals PsSuspend Execution · test · medium · {"category":"process_creation","product":"windows"}
- Potential CobaltStrike Service Installations - Registry · test · high · {"category":"registry_set","product":"windows"}
- ServiceDll Hijack · test · medium · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0552 Detection of Windows Service Creation or Modification
AN1527 Analytic 1527
Detects creation or modification of Windows Services through command-line tools (e.g., `sc.exe`, `powershell.exe`), Registry key changes under `HKLM\System\CurrentControlSet\Services`, and service execution under SYSTEM with unsigned or anomalous binary paths. Detects privilege escalation via driver installation or `CreateServiceW` usage. Correlates parent-child lineage, startup behavior, and rare service names.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- Carbanak · G0008
- APT3 · G0022
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- FIN7 · G0046
- OilRig · G0049
- APT32 · G0050
- PROMETHIUM · G0056
- APT19 · G0073
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- DarkVishnya · G0105
- Blue Mockingbird · G0108
- TeamTNT · G0139
- Aquatic Panda · G0143
- Earth Lusca · G1006
- Cinnamon Tempest · G1021
- Agrius · G1030
- BlackByte · G1043
- Medusa Group · G1051
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.