Suspicious Service ImagePath Pointing to ShieldNetWork Driver via Registry

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-09-24
Updated
2026-09-24

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects creation or modification of a service ImagePath value that references the ShieldNetWork directory, the mechanism HotPage uses to register a randomly named service that loads its vulnerable driver. Legitimate services do not install binaries under C:\Windows\ShieldNetWork. This indicates kernel-driver persistence supporting privileged ad injection and hooking.

Related detections9 linkedT1112 — drag to rearrange
Suspicious Service Registration via Svchost netsvcs Registry Modification
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious Impacket SMBexec Service Creation - Registry (via registry_event)
Malicious Impacket SMBexec Service Registration - Native (via security)
Suspicious Windows Service Trigger Configuration via Registry Modification
Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine
Windows Registry Persistence via UMe/UT Run Keys
Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)
Suspicious Service ImagePath Pointing to ShieldNetWork Driver via Registry
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.