Windows Service Creation: ServiceName javamtsup (Event ID 4697)

Flags Windows Security Event 4697 when a service named "javamtsup" is installed, indicating potential persistence.

FreeReviewedSigma · Critical · v5
Product
windows
Service
security
Author
Florian Roth (Nextron Systems), Daniil Yugoslavskiy, oscd.community (update) (SigmaHQ), DRL 1.1
Published
2017-03-27
Updated
2026-07-31

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags creation of a Windows service specifically named "javamtsup" using Security audit Event ID 4697. Attackers may use Windows services to establish persistence and execute code under the service control manager. The detection relies on Windows Security logs that include the EID 4697 service installation event and the recorded ServiceName field.

Related detections9 linkedT1543.003 — drag to rearrange
Windows System Service Installation of Remote Access Tool Services (Event 7045/7036)
Windows Security Event 4697 Service Install of Remote Access Tools
Windows Service Control Manager detects Sliver C2 default service installations via service creation events
Windows Registry Service Install Indicators for Cobalt Strike Staging
Windows Service Control Manager: ProcessHacker service runs as LocalSystem
Windows Service Control Manager Events: Suspicious Service Install Paths used by Cobalt Strike
Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Suspicious Service DLL Hijack of IKEEXT or PrintNotify
Service Hiding via SC Sdset Security Descriptor Modification
Windows Service Creation: ServiceName javamtsup (Event ID 4697)
Pivot detection · T1543.003 · 9 related

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.