ServiceDll Hijack
Description
Detects changes to the "ServiceDLL" value related to a service in the registry. This is often used as a method of persistence.
Query · sigma
selection: TargetObject|contains|all: - \System\ - ControlSet - \Services\ TargetObject|endswith: \Parameters\ServiceDll filter_main_printextensionmanger: Details: C:\Windows\system32\spool\drivers\x64\3\PrintConfig.dll filter_main_domain_controller: Image: C:\Windows\system32\lsass.exe TargetObject|endswith: \Services\NTDS\Parameters\ServiceDll Details: '%%systemroot%%\system32\ntdsa.dll' filter_main_poqexec: Image: C:\Windows\System32\poqexec.exe filter_optional_safetica: Image|endswith: \regsvr32.exe Details: C:\Windows\System32\STAgent.dll condition: selection and not 1 of filter_main_* and not 1 of filter_optional_*
Known false positives
- Administrative scripts
- Installation of a service