Windows Service Control Manager Event 7045 for smbexec.py-style service name and BAT deletion command
Flags suspicious Windows service installations matching a specific service name and BAT/delete command patterns in Event 7045.
FreeUnreviewedSigmahighv1
windows-service-control-manager-event-7045-for-smbexec-py-style-service-name-and-52a85084
title: Windows Service Control Manager Event 7045 for smbexec.py-style service name and BAT deletion command
id: 111a47ef-90c3-41d3-aabc-c5ee98847729
status: test
description: This rule identifies Windows service creation events (EventID 7045) where the Service Control Manager creates a specific service name and the service image path contains command-line patterns consistent with smbexec.py-style remote execution and cleanup. Attackers may use this technique to run commands on remote Windows hosts via a newly installed service, enabling lateral movement and execution while leaving minimal artifacts. It relies on Windows System telemetry from the Service Control Manager, specifically EventID 7045 with matching ServiceName and ImagePath content.
references:
- https://blog.ropnop.com/using-credentials-to-own-windows-boxes-part-2-psexec-and-services/
- https://github.com/fortra/impacket/blob/33058eb2fde6976ea62e04bc7d6b629d64d44712/examples/smbexec.py#L286-L296
- https://github.com/fortra/impacket/blob/edef71f17bc1240f9f8c957bbda98662951ac3ec/examples/smbexec.py#L60
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/system/service_control_manager/win_system_hack_smbexec.yml
author: Omer Faruk Celik, Huntrule Team
date: 2018-03-20
modified: 2023-11-09
tags:
- attack.lateral-movement
- attack.execution
- attack.t1021.002
- attack.t1569.002
logsource:
product: windows
service: system
detection:
selection_eid:
Provider_Name: Service Control Manager
EventID: 7045
selection_service_name:
ServiceName: BTOBTO
selection_service_image:
ImagePath|contains:
- ".bat & del "
- __output 2^>^&1 >
condition: selection_eid and 1 of selection_service_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
related:
- id: 52a85084-6989-40c3-8f32-091e12e13f09
type: derived
What it detects
This rule identifies Windows service creation events (EventID 7045) where the Service Control Manager creates a specific service name and the service image path contains command-line patterns consistent with smbexec.py-style remote execution and cleanup. Attackers may use this technique to run commands on remote Windows hosts via a newly installed service, enabling lateral movement and execution while leaving minimal artifacts. It relies on Windows System telemetry from the Service Control Manager, specifically EventID 7045 with matching ServiceName and ImagePath content.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.