New Service Creation Using Sc.EXE

Rule Info

Name
New Service Creation Using Sc.EXE
Author
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community
Description
Detects the creation of a new service using the "sc.exe" utility.
Date
2023-02-20 00:00:00
Modified
None
Id
85ff530b-261d-48c6-a441-facaa2e81e48
Tags
attack.persistence attack.privilege-escalation attack.t1543.003
Type
Community Rule

Rule History

Author
Title
Date
Commit
Nasreddine Bencherchali
Merge PR #4950 from @nasbench - Comply With v2 Spec Changes
2024-08-12
Nasreddine Bencherchali
feat: multiple fixes and updates
2023-02-21
frack113
order yaml
2022-10-28
Nasreddine Bencherchali
New Rules + Update
2022-07-14
Nasreddine Bencherchali
Update Ref+Selection 2
2022-07-11
frack113
Normalization of rule names
2022-02-22
frack113
remove invalid tag
2022-01-19
frack113
Change status for old rules
2021-11-27
frack113
Change status for old rules
2021-11-27
leegengyu
Updated ART reference links from .yaml
2021-07-06
Yugoslavskiy Daniil
review windows/process_creation part 4
2020-09-02
Bar Haim
Update win_new_service_creation.yml
2020-08-16
Ivan Kirillov
Fixed indentation
2020-06-16
Ivan Kirillov
Initial round of subtechnique updates
2020-06-16
Thomas Patzke
Rule fixes
2020-02-20