1200KM / detection
T1569.002 Service Execution — Detection Rules
Detection workspace for T1569.002 Service Execution: 39 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Remote Server Service Abuse for Lateral Movement · test · high · {"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:367abb81-9844-35f1-ad32-98f038001003"}
- MITRE BZAR Indicators for Execution · test · medium · {"product":"zeek","service":"dce_rpc"}
- DNS Events Related To Mining Pools · test · low · {"service":"dns","product":"zeek"}
- CobaltStrike Service Installations - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Credential Dumping Tools Service Execution - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Metasploit Or Impacket Service Installation Via SMB PsExec · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- PowerShell Scripts Installed as Services - Security · test · high · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- Remote Access Tool Services Have Been Installed - Security · test · medium · {"product":"windows","service":"security","definition":"The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697"}
- CobaltStrike Service Installations - System · test · critical · {"product":"windows","service":"system"}
- smbexec.py Service Installation · test · high · {"product":"windows","service":"system"}
- Credential Dumping Tools Service Execution - System · test · high · {"product":"windows","service":"system"}
- PowerShell Scripts Installed as Services · test · high · {"product":"windows","service":"system"}
- CSExec Service Installation · test · medium · {"product":"windows","service":"system"}
- HackTool Service Registration or Execution · test · high · {"product":"windows","service":"system"}
- PAExec Service Installation · test · medium · {"product":"windows","service":"system"}
- ProcessHacker Privilege Elevation · test · high · {"product":"windows","service":"system"}
- RemCom Service Installation · test · medium · {"product":"windows","service":"system"}
- Remote Access Tool Services Have Been Installed - System · test · medium · {"product":"windows","service":"system"}
- Sliver C2 Default Service Installation · test · high · {"product":"windows","service":"system"}
- PsExec Service Installation · test · medium · {"product":"windows","service":"system"}
- PSExec and WMI Process Creations Block · test · high · {"product":"windows","service":"windefend","definition":"Requirements:Enabled Block process creations originating from PSExec and WMI commands from Attack Surface Reduction (GUID: d1e49aac-8f56-4280-b9ba-993a6d77406c)"}
- CSExec Service File Creation · test · medium · {"category":"file_event","product":"windows"}
- RemCom Service File Creation · test · medium · {"category":"file_event","product":"windows"}
- PsExec Service File Creation · test · low · {"category":"file_event","product":"windows"}
- PUA - CSExec Default Named Pipe · test · medium · {"product":"windows","category":"pipe_created","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"}
- PUA - PAExec Default Named Pipe · test · medium · {"category":"pipe_created","product":"windows","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"}
- PUA - RemCom Default Named Pipe · test · medium · {"product":"windows","category":"pipe_created","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"}
- PsExec Tool Execution From Suspicious Locations - PipeName · test · medium · {"category":"pipe_created","product":"windows","definition":"Note that you have to configure logging for Named Pipe Events in Sysmon config (Event ID 17 and Event ID 18). The basic configuration is in popular sysmon configuration (https://github.com/SwiftOnSecurity/sysmon-config), but it is worth verifying. You can also use other repo, e.g. https://github.com/Neo23x0/sysmon-config, https://github.com/olafhartong/sysmon-modular. How to test detection? You can check powershell script from this site https://svch0st.medium.com/guide-to-named-pipes-and-hunting-for-cobalt-strike-pipes-dc46b2c5f575"}
- HackTool - SharpUp PrivEsc Tool Execution · test · critical · {"category":"process_creation","product":"windows"}
- Start Windows Service Via Net.EXE · test · low · {"category":"process_creation","product":"windows"}
- PUA - CsExec Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA - NirCmd Execution · test · medium · {"category":"process_creation","product":"windows"}
- PUA - NirCmd Execution As LOCAL SYSTEM · test · high · {"category":"process_creation","product":"windows"}
- PUA - NSudo Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA - RunXCmd Execution · test · high · {"category":"process_creation","product":"windows"}
- Rundll32 Execution Without Parameters · test · high · {"category":"process_creation","product":"windows"}
- Potential CobaltStrike Service Installations - Registry · test · high · {"category":"registry_set","product":"windows"}
- PowerShell as a Service in Registry · test · high · {"category":"registry_set","product":"windows"}
- WFP Filter Added via Registry · experimental · medium · {"category":"registry_set","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0421 Detection Strategy for System Services Service Execution
AN1185 Analytic 1185
Detection focuses on abnormal service executions initiated via service control manager APIs, sc.exe, net.exe, or PsExec creating temporary services. Defenders observe process creation of services.exe spawning non-standard binaries, registry changes in service keys followed by rapid execution, and network connections originating from processes tied to transient services. Correlation across process lineage, registry activity, and service logs provides strong signals of malicious service execution.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.