Windows Security Event 4697: Detects Suspicious Service Installations with C2 PowerShell Payloads

Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.

FreeUnreviewedSigmahighv1
title: "Windows Security Event 4697: Detects Suspicious Service Installations with C2 PowerShell Payloads"
id: fc555dda-7a90-4c8f-b169-12a6669a873c
related:
  - id: 5a105d34-05fc-401e-8553-272b45c1522d
    type: derived
  - id: d7a95147-145f-4678-b85d-d1ff4a3bb3f6
    type: derived
status: test
description: This rule matches Windows System Security audit Event ID 4697 for service creation events where the service binary name contains patterns consistent with ADMIN$ remote execution and PowerShell command usage. It also flags cases where the service command line includes hidden, encoded PowerShell and a specific base64 offset pattern tied to an in-memory download-and-execute sequence. Service installation abuse matters because attackers can establish persistence or enable privilege escalation and lateral movement via newly created services. The detection relies on Security log telemetry for service install events (EID 4697) and string matches against the recorded service filename/command content.
references:
  - https://www.sans.org/webcasts/119395
  - https://www.crowdstrike.com/blog/getting-the-bacon-from-cobalt-strike-beacon/
  - https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_cobaltstrike_service_installs.yml
author: Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule Team
date: 2021-05-26
modified: 2022-11-27
tags:
  - attack.persistence
  - attack.execution
  - attack.privilege-escalation
  - attack.lateral-movement
  - attack.t1021.002
  - attack.t1543.003
  - attack.t1569.002
logsource:
  product: windows
  service: security
  definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
detection:
  event_id:
    EventID: 4697
  selection1:
    ServiceFileName|contains|all:
      - ADMIN$
      - .exe
  selection2:
    ServiceFileName|contains|all:
      - "%COMSPEC%"
      - start
      - powershell
  selection3:
    ServiceFileName|contains: powershell -nop -w hidden -encodedcommand
  selection4:
    ServiceFileName|base64offset|contains: "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:"
  condition: event_id and 1 of selection*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule matches Windows System Security audit Event ID 4697 for service creation events where the service binary name contains patterns consistent with ADMIN$ remote execution and PowerShell command usage. It also flags cases where the service command line includes hidden, encoded PowerShell and a specific base64 offset pattern tied to an in-memory download-and-execute sequence. Service installation abuse matters because attackers can establish persistence or enable privilege escalation and lateral movement via newly created services. The detection relies on Security log telemetry for service install events (EID 4697) and string matches against the recorded service filename/command content.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.