Uncommon Service Installation Image Path
Description
Detects uncommon service installation commands by looking at suspicious or uncommon image path values containing references to encoded powershell commands, temporary paths, etc.
Query · sigma
selection: Provider_Name: Service Control Manager EventID: 7045 suspicious_paths: ImagePath|contains: - \\\\.\\pipe - \Users\Public\ - \Windows\Temp\ suspicious_encoded_flag: ImagePath|contains: ' -e' suspicious_encoded_keywords: ImagePath|contains: - ' aQBlAHgA' - ' aWV4I' - ' IAB' - ' JAB' - ' PAA' - ' SQBFAFgA' - ' SUVYI' filter_optional_thor_remote: ImagePath|startswith: C:\WINDOWS\TEMP\thor10-remote\thor64.exe filter_main_defender_def_updates: ImagePath|startswith: C:\ProgramData\Microsoft\Windows Defender\Definition Updates\ condition: selection and ( suspicious_paths or all of suspicious_encoded_* ) and not 1 of filter_main_* and not 1 of filter_optional_*
Known false positives
- Unknown