Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.
- Product
- windows
- Service
- security
- Author
- Florian Roth (Nextron Systems), Wojciech Lesicki (SigmaHQ), DRL 1.1
- Published
- 2021-05-26
- Updated
- 2026-07-31
ATT&CK techniques
Execution → Lateral MovementRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Windows service creation events (Security Event ID 4697) where the installed service binary name matches patterns consistent with Cobalt Strike beacon-related commands. Such service installs can provide persistence or enable privilege escalation and lateral movement by executing attacker-controlled payloads as a Windows service. The detection relies on Security audit telemetry that records service creation (EID 4697) and inspects the ServiceFileName field for suspicious executable and PowerShell/encoded-command characteristics.
Reporting behind it
- sans.orghttps://www.sans.org/webcasts/119395
- crowdstrike.comhttps://www.crowdstrike.com/blog/getting-the-bacon-from-cobalt-strike-beacon/
- thedfirreport.comhttps://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_cobaltstrike_service_installs.yml
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
id: fc555dda-7a90-4c8f-b169-12a6669a873c
related:
- id: 5a105d34-05fc-401e-8553-272b45c1522d
type: derived
- id: d7a95147-145f-4678-b85d-d1ff4a3bb3f6
type: derived
status: test
description: This rule flags Windows service creation events (Security Event ID 4697) where the installed service binary name matches patterns consistent with Cobalt Strike beacon-related commands. Such service installs can provide persistence or enable privilege escalation and lateral movement by executing attacker-controlled payloads as a Windows service. The detection relies on Security audit telemetry that records service creation (EID 4697) and inspects the ServiceFileName field for suspicious executable and PowerShell/encoded-command characteristics.
references:
- https://www.sans.org/webcasts/119395
- https://www.crowdstrike.com/blog/getting-the-bacon-from-cobalt-strike-beacon/
- https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_cobaltstrike_service_installs.yml
author: Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule Team
date: 2021-05-26
modified: 2022-11-27
tags:
- attack.persistence
- attack.execution
- attack.privilege-escalation
- attack.lateral-movement
- attack.t1021.002
- attack.t1543.003
- attack.t1569.002
logsource:
product: windows
service: security
definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
detection:
event_id:
EventID: 4697
selection1:
ServiceFileName|contains|all:
- ADMIN$
- .exe
selection2:
ServiceFileName|contains|all:
- "%COMSPEC%"
- start
- powershell
selection3:
ServiceFileName|contains: powershell -nop -w hidden -encodedcommand
selection4:
ServiceFileName|base64offset|contains: "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:"
condition: event_id and 1 of selection*
falsepositives:
- Unknown
level: high
license: DRL-1.1