Windows Security Event 4656: Non-system handle failure to SCM database object

Alerts on failed SCM database handle requests for ServicesActive from non-system logons using Windows Security Event ID 4656.

FreeReviewedSigma · Medium · v2
Product
windows
Service
security
Author
Roberto Rodriguez @Cyb3rWard0g (SigmaHQ), DRL 1.1
Published
2019-08-12
Updated
2026-07-31

ATT&CK techniques

Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Priv Esc

  7. Defense Evasion

  8. Cred Access

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies Windows Security auditing events where access attempts to the Service Control Manager database object named ServicesActive fail, using the specified AccessMask. Attackers may probe or enumerate SCM-related resources and can trigger handle acquisition failures during discovery or interaction attempts. It relies on Security log EventID 4656 telemetry, filtering specifically for non-system subjects and matching the SCM object type and name.

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.