Unusual Service Deployment Image Path (via system)

This rule detects uncommon service installation commands by looking at anomalous or uncommon image path values containing references to encoded powershell commands, temporary paths, etc.

SigmamediumWindowsv1
sigma
title: Unusual Service Deployment Image Path (via system)
id: a35095c2-7689-527d-a906-31da3613341d
status: stable
description: This rule detects uncommon service installation commands by looking at anomalous or uncommon image path values containing references to encoded powershell commands, temporary paths, etc.
references:
    - https://attack.mitre.org/techniques/T1543/003/
    - Internal Research
author: Huntrule Team
date: 2026-03-16
tags:
    - attack.persistence
    - attack.privilege-escalation
    - car.2013-09-005
    - attack.t1543.003
logsource:
    product: windows
    service: system
detection:
    selection:
        Provider_Name: 'Service Control Manager'
        EventID: 7045
    suspicious_paths:
        ImagePath|contains:
            - '\\\\.\\pipe'
            - '\Users\Public\'
            - '\Windows\Temp\'
    suspicious_encoded_flag:
        ImagePath|contains: ' -e'
    suspicious_encoded_keywords:
        ImagePath|contains:
            - ' aQBlAHgA'
            - ' aWV4I'
            - ' IAB'
            - ' JAB'
            - ' PAA'
            - ' SQBFAFgA'
            - ' SUVYI'
    filter_optional_thor_remote:
        ImagePath|startswith: 'C:\WINDOWS\TEMP\thor10-remote\thor64.exe'
    filter_main_defender_def_updates:
        ImagePath|startswith: 'C:\ProgramData\Microsoft\Windows Defender\Definition Updates\'
    condition: selection and ( suspicious_paths or all of suspicious_encoded_* ) and not 1 of filter_main_* and not 1 of filter_optional_*
falsepositives:
    - Unknown
level: medium

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.