PowerShell Set-Service SecurityDescriptorSddl DACL Modification for Windows Services
Detects PowerShell Set-Service commands with SecurityDescriptorSddl SDDL patterns that modify Windows service DACLs.
FreeUnreviewedSigmahighv1
powershell-set-service-securitydescriptorsddl-dacl-modification-for-windows-serv-a95b9b42
title: PowerShell Set-Service SecurityDescriptorSddl DACL Modification for Windows Services
id: e0958a8f-3304-4a74-8cf1-ea94fcfc90f1
related:
- id: 99cf1e02-00fb-4c0d-8375-563f978dfd37
type: derived
- id: a95b9b42-1308-4735-a1af-abb1c5e6f5ac
type: derived
status: test
description: This rule flags PowerShell executions of Set-Service that include the SecurityDescriptorSddl flag and specific SDDL patterns indicative of service DACL changes. Attackers can use service security descriptor modifications to restrict access, hide operational visibility, or prevent stopping services, supporting persistence and privilege abuse. The detection relies on process creation telemetry with command-line content identifying pwsh.exe and the presence of Set-Service parameters and SDDL fragments.
references:
- https://www.sans.org/blog/red-team-tactics-hiding-windows-services/
- https://learn.microsoft.com/pt-br/windows/win32/secauthz/sid-strings
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_service_dacl_modification_set_service.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-10-18
tags:
- attack.privilege-escalation
- attack.persistence
- attack.t1543.003
logsource:
category: process_creation
product: windows
detection:
selection_img:
- Image|endswith: \pwsh.exe
- OriginalFileName: pwsh.dll
selection_sddl_flag:
CommandLine|contains:
- "-SecurityDescriptorSddl "
- "-sd "
selection_set_service:
CommandLine|contains|all:
- "Set-Service "
- D;;
CommandLine|contains:
- ;;;IU
- ;;;SU
- ;;;BA
- ;;;SY
- ;;;WD
condition: all of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule flags PowerShell executions of Set-Service that include the SecurityDescriptorSddl flag and specific SDDL patterns indicative of service DACL changes. Attackers can use service security descriptor modifications to restrict access, hide operational visibility, or prevent stopping services, supporting persistence and privilege abuse. The detection relies on process creation telemetry with command-line content identifying pwsh.exe and the presence of Set-Service parameters and SDDL fragments.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.