Rule Info
Name
Service Startup Type Change Via Wmic.EXE
Author
Swachchhanda Shrawan Poudel (Nextron Systems)
Description
Detects changes to service startup type to 'disabled' or 'manual' using the WMIC command-line utility.
Reference
Date
2026-04-27 00:00:00
Modified
None
Id
c0514f28-fdae-42df-b886-06e2b2bc5b37
Tags
attack.execution attack.defense-impairment attack.t1047 attack.t1685
Type
Community Rule
Link to Public Repo
