Windows Reg.exe Modifies Service ImagePath in HKLM\SYSTEM\CurrentControlSet\Services

Alerts on reg.exe commands that target HKLM\SYSTEM\CurrentControlSet\Services\ImagePath modifications.

FreeReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
frack113 (SigmaHQ), DRL 1.1
Published
2021-12-30
Updated
2026-07-30

ATT&CK techniques

Execution → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule identifies executions of reg.exe that attempt to modify an existing Windows service ImagePath value stored under HKLM\SYSTEM\CurrentControlSet\Services. Attackers can abuse registry permissions to redirect the service to a different executable, causing their code to run when the service starts. It relies on process creation telemetry, specifically reg.exe command-line arguments containing the targeted service registry path and ImagePath field.

Related detections9 linkedT1574.011 — drag to rearrange
Malicious ServiceDll Hijack with QSC Loader DLL
Windows Service Registry Key ReadControl Access (Event ID 4663)
Windows sc.exe Service Security Descriptor Tampering (sdset)
PowerShell: Suspicious Set-Service DACL/SecurityDescriptor Modification for Hidden Services
Windows PowerShell Set-Service SDDL Usage to Hide Services
PowerShell Set-Service SecurityDescriptor (DCLCWPDTSD) to Hide Services
Windows PowerShell ScriptBlock checks for service registry ACL inspection
Windows: Detect sc.exe Service Creation with DACL Modification (sdset DCLCWPDTSD)
Windows service configuration tampering via sc/reg with payload execution paths
Windows Reg.exe Modifies Service ImagePath in HKLM\SYSTEM\CurrentControlSet\Services
Pivot detection · T1574.011 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.