Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads

Flags Windows Event 4697 service installs whose service command strings match hidden/encoded PowerShell payload patterns.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Florian Roth (Nextron Systems), Wojciech Lesicki (SigmaHQ), DRL 1.1
Published
2021-05-26
Updated
2026-07-31
title: Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
id: fc555dda-7a90-4c8f-b169-12a6669a873c
related:
  - id: 5a105d34-05fc-401e-8553-272b45c1522d
    type: derived
  - id: d7a95147-145f-4678-b85d-d1ff4a3bb3f6
    type: derived
status: test
description: This rule flags Windows service creation events (Security Event ID 4697) where the installed service binary name matches patterns consistent with Cobalt Strike beacon-related commands. Such service installs can provide persistence or enable privilege escalation and lateral movement by executing attacker-controlled payloads as a Windows service. The detection relies on Security audit telemetry that records service creation (EID 4697) and inspects the ServiceFileName field for suspicious executable and PowerShell/encoded-command characteristics.
references:
  - https://www.sans.org/webcasts/119395
  - https://www.crowdstrike.com/blog/getting-the-bacon-from-cobalt-strike-beacon/
  - https://thedfirreport.com/2021/08/29/cobalt-strike-a-defenders-guide/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/security/win_security_cobaltstrike_service_installs.yml
author: Florian Roth (Nextron Systems), Wojciech Lesicki, Huntrule Team
date: 2021-05-26
modified: 2022-11-27
tags:
  - attack.persistence
  - attack.execution
  - attack.privilege-escalation
  - attack.lateral-movement
  - attack.t1021.002
  - attack.t1543.003
  - attack.t1569.002
logsource:
  product: windows
  service: security
  definition: The 'System Security Extension' audit subcategory need to be enabled to log the EID 4697
detection:
  event_id:
    EventID: 4697
  selection1:
    ServiceFileName|contains|all:
      - ADMIN$
      - .exe
  selection2:
    ServiceFileName|contains|all:
      - "%COMSPEC%"
      - start
      - powershell
  selection3:
    ServiceFileName|contains: powershell -nop -w hidden -encodedcommand
  selection4:
    ServiceFileName|base64offset|contains: "IEX (New-Object Net.Webclient).DownloadString('http://127.0.0.1:"
  condition: event_id and 1 of selection*
falsepositives:
  - Unknown
level: high
license: DRL-1.1