KrbRelayUp Service Installation - Native (via system)

PremiumReviewedSigma · High · v1
Product
windows
Service
system
Author
HuntRule
Published
2026-08-19
Updated
2026-08-28

ATT&CK techniques

Execution
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Persistence

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule detects escalate privileges while abusing KrbRelayUp attack.

Related detections6 linkedT1569 — drag to rearrange
Obfuscated Massive Service Failures - Tchopper (via system)
Malicious Massive Remote Service Creation via Named Pipes - TChopper, CME (via security)
Malicious Massive Remote Service Creation via Named Pipes - Tchopper (via security)
Windows Print Spooler Exploitation Indicators: UNIDRV.DLL and mimispool Driver Loads (Event ID 316)
Windows Print Spooler Plugin Load Errors Indicative of CVE-2021-1675 Exploitation
Windows PsExec Execution Triggered by psexec.exe Process Creation
KrbRelayUp Service Installation - Native (via system)
Pivot detection · T1569 · 6 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.