1200KM / detection
T1574.011 Services Registry Permissions Weakness — Detection Rules
Detection workspace for T1574.011 Services Registry Permissions Weakness: 11 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Service Registry Key Read Access Request · test · low · {"product":"windows","service":"security","definition":"Requirements: SACLs must be enabled for \"READ_CONTROL\" on the registry keys used in this rule"}
- Service Registry Permissions Weakness Check · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Suspicious Service DACL Modification Via Set-Service Cmdlet - PS · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Abuse of Service Permissions to Hide Services Via Set-Service - PS · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Abuse of Service Permissions to Hide Services Via Set-Service · test · high · {"category":"process_creation","product":"windows"}
- Changing Existing Service ImagePath Value Via Reg.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential Privilege Escalation via Service Permissions Weakness · test · high · {"product":"windows","category":"process_creation"}
- Possible Privilege Escalation via Weak Service Permissions · test · high · {"category":"process_creation","product":"windows"}
- Service DACL Abuse To Hide Services Via Sc.EXE · test · high · {"category":"process_creation","product":"windows"}
- Service Security Descriptor Tampering Via Sc.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Potential Persistence Attempt Via Existing Service Tampering · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0427 Detection Strategy for Hijack Execution Flow through Service Registry Premission Weakness.
AN1195 Analytic 1195
Unauthorized modification of service-related registry keys such as ImagePath, FailureCommand, ServiceDll, or Performance/Parameters keys. Defender correlates registry modifications, anomalous service metadata changes, and subsequent service process executions that deviate from baseline configurations.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1574.011 simulation workspace
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.