Windows Service Control Manager detects Sliver C2 default service installations via service creation events

Alerts on Service Control Manager EventID 7045 for Sliver service installations using a known Temp-staged EXE path pattern.

FreeReviewedSigma · High · v2
Product
windows
Service
system
Author
Florian Roth (Nextron Systems), Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-08-25
Updated
2026-07-31

ATT&CK techniques

Execution → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Defense Evasion

  5. Cred Access

  6. Discovery

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags Windows Service Control Manager events where a new service is installed with a ServiceName matching Sliver ("Sliver" or "Sliver implant") and the service binary is created from a short-named executable in \Windows\Temp. Such service installations can provide attackers persistence and reliable command execution as Windows services. Detection relies on telemetry from System service creation events (EventID 7045) including ServiceName and ImagePath.

Related detections9 linkedT1543.003 — drag to rearrange
Windows System Service Installation of Remote Access Tool Services (Event 7045/7036)
Windows Security Event 4697 Service Install of Remote Access Tools
Windows Registry Service Install Indicators for Cobalt Strike Staging
Windows Service Control Manager: ProcessHacker service runs as LocalSystem
Windows Service Control Manager Events: Suspicious Service Install Paths used by Cobalt Strike
Windows Security 4697 Alerts for Service Installations Using Cobalt Strike Beacon Payloads
Windows Service Creation: ServiceName javamtsup (Event ID 4697)
Suspicious PsExec Service Named Sliver
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Windows Service Control Manager detects Sliver C2 default service installations via service creation events
Pivot detection · T1543.003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.