Windows Service Configuration Tampering by Medium-Integrity Processes

Alerts on medium-integrity processes running commands that target registry service configuration values for potential privilege escalation.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Teymur Kheirkhabarov (SigmaHQ), DRL 1.1
Published
2019-10-26
Updated
2026-07-30
title: Windows Service Configuration Tampering by Medium-Integrity Processes
id: 33bc4638-2f08-41bc-b12e-5d76c94b13d6
status: test
description: This rule flags process executions where the command line includes registry paths for ControlSet services and references service configuration values (ImagePath, FailureCommand, and ServiceDll). Attackers can use these changes to persist malicious execution and potentially gain elevated execution by weakening how services are configured. The detection relies on process creation telemetry, specifically the process command line content and the initiating process integrity level (Medium or S-1-16-8192).
references:
  - https://speakerdeck.com/heirhabarov/hunting-for-privilege-escalation-in-windows-environment
  - https://pentestlab.blog/2017/03/31/insecure-registry-permissions/
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_registry_privilege_escalation_via_service_key.yml
author: Teymur Kheirkhabarov, Huntrule Team
date: 2019-10-26
modified: 2024-12-01
tags:
  - attack.persistence
  - attack.privilege-escalation
  - attack.execution
  - attack.stealth
  - attack.t1574.011
logsource:
  product: windows
  category: process_creation
detection:
  selection:
    IntegrityLevel:
      - Medium
      - S-1-16-8192
    CommandLine|contains|all:
      - ControlSet
      - services
    CommandLine|contains:
      - \ImagePath
      - \FailureCommand
      - \ServiceDll
  condition: selection
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 0f9c21f1-6a73-4b0e-9809-cb562cb8d981
    type: derived