Windows Security Event 4697: Detects Suspicious Service Installations with C2 PowerShell Payloads
Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.
FreeUnreviewedSigmahighv1
windows-security-event-4697-detects-suspicious-service-installations-with-c2-pow-d7a95147
title: "Windows Security Event 4697: Detects Suspicious Service Installations with C2 PowerShell Payloads"
id: fc555dda-7a90-4c8f-b169-12a6669a873c
related:
- id: 5a105d34-05fc-401e-8553-272b45c1522d
type: derived
- id: d7a95147-145f-4678-b85d-d1ff4a3bb3f6
type: derived
status: test
description: This rule matches Windows System Security audit Event ID 4697 for service creation events where the service binary name contains patterns consistent with ADMIN$ remote execution and PowerShell command usage. It also flags cases where the service command line includes hidden, encoded PowerShell and a specific base64 offset pattern tied to an in-memory download-and-execute sequence. Service installation abuse matters because attackers can establish persistence or enable privilege escalation and lateral movement via newly created services. The detection relies on Security log telemetry for service install events (EID 4697) and string matches against the recorded service filename/command content.
references:
- https://www.sans.org/webcasts/119395
- https://www.crowdstrike.com/blog/getting-the-bacon-from-cobalt-strike-beacon/
- https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_cobaltstrike_service_installs.yml
author: Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule Team
date: 2021-05-26
modified: 2022-11-27
tags:
- attack.persistence
- attack.execution
- attack.privilege-escalation
- attack.lateral-movement
- attack.t1021.002
- attack.t1543.003
- attack.t1569.002
logsource:
product: windows
service: security
definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
detection:
event_id:
EventID: 4697
selection1:
ServiceFileName|contains|all:
- ADMIN$
- .exe
selection2:
ServiceFileName|contains|all:
- "%COMSPEC%"
- start
- powershell
selection3:
ServiceFileName|contains: powershell -nop -w hidden -encodedcommand
selection4:
ServiceFileName|base64offset|contains: "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:"
condition: event_id and 1 of selection*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule matches Windows System Security audit Event ID 4697 for service creation events where the service binary name contains patterns consistent with ADMIN$ remote execution and PowerShell command usage. It also flags cases where the service command line includes hidden, encoded PowerShell and a specific base64 offset pattern tied to an in-memory download-and-execute sequence. Service installation abuse matters because attackers can establish persistence or enable privilege escalation and lateral movement via newly created services. The detection relies on Security log telemetry for service install events (EID 4697) and string matches against the recorded service filename/command content.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.