Suspicious Service Installed
Description
Detects installation of NalDrv or PROCEXP152 services via registry-keys to non-system32 folders. Both services are used in the tool Ghost-In-The-Logs (https://github.com/bats3c/Ghost-In-The-Logs), which uses KDU (https://github.com/hfiref0x/KDU)
Query · sigma
selection: TargetObject: - HKLM\System\CurrentControlSet\Services\NalDrv\ImagePath - HKLM\System\CurrentControlSet\Services\PROCEXP152\ImagePath filter: Image|endswith: - \procexp64.exe - \procexp64a.exe - \procexp.exe - \procmon64.exe - \procmon64a.exe - \procmon.exe - \handle.exe - \handle64.exe - \handle64a.exe Details|contains: \WINDOWS\system32\Drivers\PROCEXP152.SYS condition: selection and not filter
Known false positives
- Other legimate tools using this service names and drivers. Note - clever attackers may easily bypass this detection by just renaming the services. Therefore just Medium-level and don't rely on it.