System Services T1569

Tactic: Execution

Adversaries may abuse system services or daemons to execute commands or programs. Adversaries can execute malicious content by interacting with or creating services either locally or remotely. Many services are set to run at boot, which can aid in achieving persistence (Create or Modify System Process), but adversaries can also abuse services for one-time or temporary execution.

Events covered

29 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 5Process terminated
SysmonEvent ID 7Image loaded
SysmonEvent ID 11FileCreate
SysmonEvent ID 12RegistryEvent (Object create and delete)
SysmonEvent ID 13RegistryEvent (Value Set)
SysmonEvent ID 14RegistryEvent (Key and Value Rename)
SysmonEvent ID 17PipeEvent (Pipe Created)
SysmonEvent ID 18PipeEvent (Pipe Connected)
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4689A process has exited.
Security-AuditingEvent ID 4697A service was installed in the system.
Security-AuditingEvent ID 5145A network share object was checked to see whether client can be granted desired access.
Defender-DeviceProcessEventsanyProcess activity
ESFexecProcess Execution
ESFforkProcess Fork
Linux-AuditdEvent ID 1327PROCTITLE
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
PrintServiceEvent ID 316Printer driver param1 for param2 param3 was added or updated.
PrintServiceEvent ID 808The print spooler failed to load a plug-in module PluginDllName, error code ErrorCode.
Windows-DefenderEvent ID 1121Microsoft Defender Exploit Guard has blocked an operation that is not allowed by your IT administrator.
RPCFWEvent ID 3An RPC server function was called.
Service-Control-ManagerEvent ID 7000The %1 service failed to start due to the following error:
Service-Control-ManagerEvent ID 7009A timeout was reached (%1 milliseconds) while waiting for the %2 service to connect
Service-Control-ManagerEvent ID 7036The Microsoft Software Shadow Copy Provider service entered the stopped state.
Service-Control-ManagerEvent ID 7045A service was installed in the system.

Authoring guide

These 106 rules share fields, values, and exclusions.

Fields filtered most (86 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine24contains 14, regex_match 8, ends_with 1, eq 1, in 1, is_not_null 1(?i)((\.exe(")?(\s+|\s+\/c)\s+)|(psexec.{1,}))|("{1,})?\x..., (?i)sc(\.exe)?\s(.+)?create\s, &, /account=system , /account=ti
EventID20eq 207045, 4688, 4697, 1, 4104
Image17ends_with 10, eq 3, contains 2, is_not_null 1, wildcard 1./*, /boot/*, /dev/shm/*, /launchctl, /usr/bin/systemctl
ServiceName15eq 9, contains 3, starts_with 2, regex_match 1, wildcard 1ammyyadmin, atera, psexesvc, sliver, (^[a-zA-Z]{4}$)|(^[a-zA-Z]{8}$)|(^[a-zA-Z]{16}$)
process_name15eq 13, in 3, ends_with 1, ne 1sc.exe, cmd.exe, curl, launchctl, psexec.exe
ImagePath13contains 6, ends_with 5, match 3, regex_match 1, starts_with 1.exe, %comspec%, .bat, .bat & del , .cmd
event.type13eq 12, in 1start, change, process_started
OriginalFileName12eq 12psexec.c, sc.exe, net.exe, net1.exe, nircmd.exe
Provider_Name12eq 12service control manager
host.os.type12eq 12
process.args8eq 6, in 2, starts_with 2, wildcard 1enable, start, */bin/base64*-d*, */bin/chmod +x*, */bin/curl*.amazonaws.com*
Channel6eq 6, in 6
EventType6eq 6, in 1, ne 1exec, creation, deletion, fork, launch_daemon
eventtype6eq 6
parent_process_name6eq 4, ends_with 1, regex_match 1services.exe, (?i)(\w{8}\.exe)|(psexec), \PSEXESVC.exe, cmd.exe, mshta.exe

Top indicator values (722 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
Provider_Nameeq
service control manager
1250
EventIDeq
7045
1121
EventIDeq
4688
6317
EventIDeq
4697
33
EventIDeq
1
2241
event.typeeq
start
111078
EventTypeeq
exec
4576
process_nameeq
sc.exe
432
AccessListcontains
%%4417
311
OriginalFileNameeq
psexec.c
37
OriginalFileNameeq
sc.exe
330
RelativeTargetNameeq
svcctl
36
ShareNamewildcard
\\*\IPC$
311
event.categoryeq
process
3142
process_namein
curl
389
CommandLineregex_match
(?i)((\.exe(")?(\s+|\s+\/c)\s+)|(psexec.{1,}))|("{1,})?\x5c\x5c.{2,}
22
CommandLineregex_match
(?i)sc(\.exe)?\s(.+)?create\s
22
Detailscontains
powershell
211
ImagePathcontains
powershell
25
PipeNameeq
\psexesvc
22
ProviderNameeq
mdatp
26
ServiceFileNamecontains
powershell
24
ServiceNamecontains
ammyyadmin
22
ServiceNamecontains
atera
22
ServiceNamecontains
basupportexpresssrvcupdater
22
ServiceNamecontains
basupportexpressstandaloneservice
22
ServiceNamecontains
chromoting
22
ServiceNamecontains
gotoassist
22
ServiceNamecontains
gotomypc
22
ServiceNamecontains
jumpcloud
22

Exclusions (189 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
SubjectUserNameends_with
$
2
CommandLineeq
"cmd.exe" /c sc control hptpsmarthealthservice 211
1
Detailswildcard
%SystemRoot%\system32\svchost.exe -k *
1
Detailswildcard
%systemroot%\system32\*.exe
1
Detailswildcard
%windir%\system32\*.exe
1
Detailswildcard
%windir%\system32\svchost.exe -k *
1
Detailswildcard
?:\Windows\system32\*.exe
1
EventDatacontains
gc_service.exe
1
EventDatacontains
gc_worker.exe
1
Hasheseq
214c75f678bc596bbe667a3b520aaaf09a0e50c364a28ac738a02f867a085eba
1
Hasheseq
23aa95b637a1bf6188b386c21c4e87967ede80242327c55447a5bb70d9439244
1
Hasheseq
3ed33e71641645367442e65dca6dab0d326b22b48ef9a4c2a2488e67383aa9a6
1
Hasheseq
5050b025909e81ae5481db37beb807a80c52fc6dd30c8aa47c9f7841e2a31be7
1
Hasheseq
b4db053f6032964df1b254ac44cb995ffaeb4f3ade09597670aba4f172cf65e4
1
Imageends_with
\system32\conhost.exe
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 56 rules

Elastic 19 rules

Splunk 26 rules

Kusto 5 rules