Suspicious Changing Existing Service ImagePath Value Through Reg.EXE (via process_creation)
This rule detects threat actors may execute their own hostile payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, to launch their own code at Service start. Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services
SigmamediumWindowsv1
sigma
suspicious-changing-existing-service-imagepath-value-through-reg-exe-via-process-creation
title: Suspicious Changing Existing Service ImagePath Value Through Reg.EXE (via process_creation)
id: 461cc95b-555c-5ec2-9aca-a6470b96755b
status: stable
description: This rule detects threat actors may execute their own hostile payloads by hijacking the Registry entries used by services. Adversaries may use flaws in the permissions for registry to redirect from the originally specified executable to one that they control, to launch their own code at Service start. Windows stores local service configuration information in the Registry under HKLM\SYSTEM\CurrentControlSet\Services
references:
- https://attack.mitre.org/techniques/T1574/011/
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1574.011/T1574.011.md#atomic-test-2---service-imagepath-change-with-regexe
author: Huntrule Team
date: 2026-01-11
tags:
- attack.privilege-escalation
- attack.persistence
- attack.execution
- attack.stealth
- attack.t1574.011
logsource:
category: process_creation
product: windows
detection:
selection:
Image|endswith: '\reg.exe'
CommandLine|contains|all:
- 'add '
- 'SYSTEM\CurrentControlSet\Services\'
- ' ImagePath '
selection_value:
CommandLine|contains|windash: ' -d '
condition: all of selection*
falsepositives:
- Unknown
level: medium
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.