Create or Modify System Process T1543

Tactics: Persistence, Privilege Escalation

Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters.

Events covered

40 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 5Process terminated
SysmonEvent ID 6Driver loaded
SysmonEvent ID 7Image loaded
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 15FileCreateStreamHash
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4674An operation was attempted on a privileged object.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4689A process has exited.
Security-AuditingEvent ID 4697A service was installed in the system.
Security-AuditingEvent ID 4698A scheduled task was created.
Security-AuditingEvent ID 4723An attempt was made to change an account's password.
Event ID 0Event ID 0
Defender-DeviceEventsExploitGuardNonMicrosoftSignedBlockedExploit Guard non-Microsoft signed image (blocked)
Defender-DeviceFileEventsanyFile activity
Defender-DeviceImageLoadEventsanyImage load
Defender-DeviceNetworkEventsanyNetwork activity
Defender-DeviceProcessEventsanyProcess activity
ESFexecProcess Execution
ESFforkProcess Fork
ESFcreateFile or Directory Create
ESFwriteFile Write
Linux-AuditdEvent ID 1300SYSCALL
Linux-AuditdEvent ID 1302PATH
Linux-AuditdEvent ID 1309EXECVE
Linux-AuditdEvent ID 1327PROCTITLE
CodeIntegrityEvent ID 3023The driver FileNameBuffer is blocked from loading as the driver has been revoked by Microsoft.
CodeIntegrityEvent ID 3077Code Integrity determined that a process (Process Name) attempted to load File Name that did not meet the Requested Signing Level signing level requirements or violated code integrity p...
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
PowerShellEvent ID 800Event ID 800
Service-Control-ManagerEvent ID 7036The Microsoft Software Shadow Copy Provider service entered the stopped state.
Service-Control-ManagerEvent ID 7045A service was installed in the system.
Sysmon-for-LinuxEvent ID 1Process Create
Sysmon-for-LinuxEvent ID 11File created

Authoring guide

These 251 rules share fields, values, and exclusions.

Fields filtered most (127 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventType72eq 45, in 26, ne 3exec, start, creation, exec_event, ProcessRollup2
host.os.type71eq 70, in 1
event.type68eq 59, ne 6, in 3start, change, creation, deletion, process_started
process_name67eq 40, in 25, starts_with 6, wildcard 5, contains 1, ends_with 1, is_not_null 1bash, csh, dash, sc.exe, cmd.exe
Image56ends_with 29, is_not_null 8, starts_with 7, wildcard 7, eq 6, contains 5, in 1, regex_match 1\sc.exe, /boot/*, /dev/shm/*, ./*, /curl
CommandLine45contains 35, regex_match 7, in 4, wildcard 4, eq 2, match 2, ends_with 1create, binpath, config, start, (?i)cmd\.exe\s+\/Q\s+\/c
parent_process_name34eq 21, in 14, contains 1, is_not_null 1, wildcard 1services.exe, systemd, bash, cron, crond
process.args34eq 20, in 8, wildcard 7, contains 6, starts_with 6, ends_with 1-c, -i, --command, --install, -cl
TargetFilename32wildcard 17, starts_with 11, ends_with 4, eq 3, contains 2, in 1/boot/efi/efi/*/grub.cfg, /boot/grub/grub.cfg, /boot/grub2/grub.cfg, /etc/systemd/system/*, /etc/systemd/user/*
EventID23eq 237045, 6, 4697, 11, 4688
ServiceName22eq 13, contains 4, in 2, starts_with 2, wildcard 1ammyyadmin, atera, krbscm, PDQDeployRunner-, ProcessHacker
OriginalFileName18eq 17, in 1sc.exe, cmd.exe, devcon.exe, gpt4all.exe, hamakaze.exe
Provider_Name17eq 17service control manager
TargetObject17wildcard 10, contains 3, ends_with 3, eq 1, starts_with 1hklm\system\*controlset*\services\*\imagepath, *\system\controlset*\services\*\imagepath, \adws, \apphostsvc, \appreadiness
ImagePath14contains 9, match 2, regex_match 2, ends_with 1, in 1, starts_with 1 -c , -e, -k , -nop , -r

Top indicator values (7589 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
431078
event.typeeq
change
894
event.typeeq
creation
853
EventTypeeq
exec
22576
EventTypeeq
connection_attempted
773
EventTypeeq
start
7391
EventTypein
exec
17201
EventTypein
start
14163
EventTypein
exec_event
10149
EventTypein
ProcessRollup2
9117
EventTypein
creation
934
EventTypein
rename
727
Provider_Nameeq
service control manager
1750
process_namein
bash
14202
process_namein
sh
14197
process_namein
zsh
14196
process_namein
csh
13159
process_namein
fish
13163
process_namein
ksh
13163
process_namein
tcsh
13156
process_namein
dash
12170
EventIDeq
7045
1221
Imageends_with
\sc.exe
1230
process_nameeq
sc.exe
1032
OriginalFileNameeq
sc.exe
930
process.code_signature.existseq
false
9119
process.code_signature.trustedeq
false
9115
CommandLinecontains
create
729
event.categoryeq
process
7142
process.argseq
-c
7107

Exclusions (1506 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagein
/bin/chef-client
13
Imagein
/bin/dnf
13
Imagein
/bin/dnf-automatic
13
Imagein
/bin/dockerd
13
Imagein
/bin/microdnf
13
Imagein
/bin/podman
13
Imagein
/bin/puppet
13
Imagein
/bin/rpm
13
Imagein
/bin/snapd
13
Imagein
/bin/yum
13
Imagein
/opt/puppetlabs/puppet/bin/puppet
13
Imagein
/sbin/apk
13
Imagein
/usr/bin/chef-client
13
Imagein
/usr/bin/dnf
13
Imagein
/usr/bin/dnf-automatic
13

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 85 rules

Elastic 112 rules

Splunk 43 rules

Kusto 8 rules

YARA-L 1 rule

Panther 2 rules