Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads

Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Florian Roth (Nextron Systems), Wojciech Lesicki (SigmaHQ), DRL 1.1
Published
2021-05-26
Updated
2026-07-31

ATT&CK techniques

Execution → Lateral Movement
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule flags Windows service creation events (Security Event ID 4697) where the installed service binary name matches patterns consistent with Cobalt Strike beacon-related commands. Such service installs can provide persistence or enable privilege escalation and lateral movement by executing attacker-controlled payloads as a Windows service. The detection relies on Security audit telemetry that records service creation (EID 4697) and inspects the ServiceFileName field for suspicious executable and PowerShell/encoded-command characteristics.

Related detections9 linkedT1569.002 — drag to rearrange
Windows Registry Service Install Indicators for Cobalt Strike Staging
Windows Service Control Manager Events: Suspicious Service Install Paths used by Cobalt Strike
Malicious PsExec Service Installation via PSEXESVC
Suspicious Lateral Movement via PsExec Service (via process_creation)
Possible PsExec Remote Service Installation with Randomly Named Service (via security)
Windows Named Pipe Creation: Default RemCom Pipe Name
Windows Named Pipe Created for CSExec Default Pipe Name
Windows System Service Installation of Remote Access Tool Services (Event 7045/7036)
Windows Security Event 4697 Service Install of Remote Access Tools
Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Pivot detection · T1569.002 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.