Malicious Service Permissions Hijacked for Privileges Abuse - Reg via PowerShell (via powershell)

PremiumReviewedSigma · High · v1
Product
windows
Service
powershell
Author
HuntRule
Published
2026-08-31
Updated
2026-08-31

ATT&CK techniques

Execution → Defense Evasion

What it detects

This rule detects modify the permissions of a service using native PowerShell commands in order to abuse its privileges. Note that it requires PowerShell 7 or higher.

Related detections9 linkedT1543.003 — drag to rearrange
Malicious Service Permissions Hijacked for Privileges Abuse - Service (via process_creation)
Malicious Service Permissions Hijacked for Privileges Abuse - Reg via Command (via process_creation)
Suspicious RustDesk Remote Access Service Installation via sc (via process_creation)
Malicious Service Creation Pointing to Public Data File via sc (via process_creation)
EAP Service Activation by Liontail Framework for DLL Sideloading - Via Command (via process_creation)
Malicious Service Abuse with Backdoored "command Failure" - Service (via process_creation)
Malicious Mimikatz Driver Registration - Reg via Sysmon (via registry_event)
Suspicious PSexec Service Installation (via security)
Suspicious Impact of 'SMOKEDHAM Backdoor' with MSDTC Service Privilege Escalation via Command Line (via process_creation)
Malicious Service Permissions Hijacked for Privileges Abuse - Reg via PowerShell (via powershell)
Pivot detection · T1543.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.