
Rule Info
Name
Suspicious Services Execution Pattern
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects suspicious service execution patterns, which could be sign of persistence or lateral movement activity.
Attackers may create or abuse existing services to execute malicious payloads or scripts with suspicious execution patterns.
Date
2025-08-29 00:00:00
Modified
None
Id
3df82a4f-74f6-4154-b01d-3f32e5de7827
Tags
attack.privilege-escalation attack.execution attack.t1543.003 attack.lateral-movement
Type
Nextron Sigma feed only (private)