Windows Process Creation: Suspicious Service Stop/Pause/Delete/Disable via net, sc, PowerShell

Alerts on net/sc/wmic/PowerShell commands that stop, pause, delete, or disable Windows services, especially security/backup services.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems), frack113 , X__Junior (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-09-01
Updated
2026-07-30

ATT&CK techniques

Impact
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Discovery

  10. Lateral Movement

  11. Collection

  12. C2

  13. Exfiltration

What it detects

This rule flags Windows process executions of common service-management utilities (net, sc, wmic, and PowerShell variants) when their command lines include actions to stop, pause, disable, remove, or delete services. It also looks for deletion/configuration patterns that indicate service tampering of specific service names, including security and backup-related services. Such activity can support defense evasion by impairing critical services, and the detection relies on process creation telemetry with command-line and image/original file name information.

Related detections9 linkedT1489 — drag to rearrange
Possible Akira Ransomware VM Shutdown via vim-cmd
Possible Ransomware Pre-Encryption VM Termination via esxcli
Malicious Massive Processes Termination Burst (via process_creation)
Malicious Service Deactivation - Command (via process_creation)
Malicious ESXi Virtual Machine Termination and Snapshot Removal
Malicious Stopping of Security or Backup Services Before Impact (via process_creation)
Malicious Massive Services Deletion Burst (via process_creation)
Malicious Security Service Tampering via wmic PathName Query (via process_creation)
Suspicious GhostLocker Watchdog Process Execution (via process_creation)
Windows Process Creation: Suspicious Service Stop/Pause/Delete/Disable via net, sc, PowerShell
Pivot detection · T1489 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.