Windows New Service Creation via sc.exe

Flags sc.exe service creation commands containing create and binPath on Windows, excluding Dropbox-launched cases.

FreeReviewedSigma · Low · v1
Product
windows
Category
process_creation
Author
Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community (SigmaHQ), DRL 1.1
Published
2023-02-20
Updated
2026-07-30

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule identifies the creation of a new Windows service executed with the sc.exe utility by matching process creation where the command line includes both the create operation and the binPath parameter. Service creation is a key mechanism for persistence and privilege impact, making misuse stand out during endpoint activity monitoring. It relies on Windows process creation telemetry, specifically the sc.exe process name/path and its command-line arguments, while excluding events spawned from Dropbox-related parent processes.

Related detections9 linkedT1543.003 — drag to rearrange
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious TinyTurla ServiceDll Registration via svchost Group (via registry_set)
Suspicious ToyMaker LAGTOY Service Creation Masquerading as WmiPrvSV via sc.exe
Malicious Service Creation With Autostart binPath via sc.exe (via process_creation)
Malicious svchost Service Creation for TinyTurla Persistence (via process_creation)
Malicious Service Creation Masquerading as nslookup (via process_creation)
Interactive Service Creation Executing cmd via sc.exe
Malicious Known Vulnerable Driver Load for BYOVD Attack
Malicious ValleyRAT KernelQuick Rootkit Service and Shellcode Store Registry Keys
Windows New Service Creation via sc.exe
Pivot detection · T1543.003 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.