Suspicious Service Registration via Svchost netsvcs Registry Modification

PremiumReviewedSigma · Medium · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-09-19
Updated
2026-09-19

ATT&CK techniques

Persistence → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects modification of the Svchost netsvcs registry value, abused by the SADBRIDGE loader to register a malicious service that is hosted by svchost.exe and delivers the GOSAR backdoor. Adding an entry to the netsvcs service group lets the attacker run code inside a trusted host process for stealthy persistence. Changes to this value outside of software installation warrant investigation.

Related detections9 linkedT1112 — drag to rearrange
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious Impacket SMBexec Service Creation - Registry (via registry_event)
Malicious Impacket SMBexec Service Registration - Native (via security)
Suspicious Windows Service Trigger Configuration via Registry Modification
Windows System Service Control Manager Event 7045 Scheduled Scan and UpdatMachine
Windows Registry Persistence via UMe/UT Run Keys
Windows Security: Detect Scheduled Task Creation for OilRig-Related Persistence
Windows Scheduled Task Process Creating autoit3.exe for nslookup TXT Queries (OilRig)
Malicious UAC Disable via EnableLUA Registry Modification via registry_set
Suspicious Service Registration via Svchost netsvcs Registry Modification
Pivot detection · T1112 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.