Configure Potentially Suspicious Failure Command For Service Via Sc.EXE

Rule Info

Name
Configure Potentially Suspicious Failure Command For Service Via Sc.EXE
Author
Nasreddine Bencherchali (Nextron Systems)
Description
Detects the execution of the "sc.exe" utility with the "failure" flag in order to configure a failure command to be executed. Attackers might configure a specific command or script to be executed service when a service fails to start in order to keep persistence on a machine.
Date
2024-04-29 00:00:00
Modified
None
Id
188ef9b3-663b-4379-bab3-35a9f4d0b32a
Tags
attack.defense_evasion
Type
Nextron Sigma feed only (private)

Rule History