Windows Service Control Manager Event 7045 for smbexec.py-style service name and BAT deletion command

Flags suspicious Windows service installations matching a specific service name and BAT/delete command patterns in Event 7045.

FreeUnreviewedSigmahighv1
title: Windows Service Control Manager Event 7045 for smbexec.py-style service name and BAT deletion command
id: 111a47ef-90c3-41d3-aabc-c5ee98847729
status: test
description: This rule identifies Windows service creation events (EventID 7045) where the Service Control Manager creates a specific service name and the service image path contains command-line patterns consistent with smbexec.py-style remote execution and cleanup. Attackers may use this technique to run commands on remote Windows hosts via a newly installed service, enabling lateral movement and execution while leaving minimal artifacts. It relies on Windows System telemetry from the Service Control Manager, specifically EventID 7045 with matching ServiceName and ImagePath content.
references:
  - https://blog.ropnop.com/using-credentials-to-own-windows-boxes-part-2-psexec-and-services/
  - https://github.com/fortra/impacket/blob/33058eb2fde6976ea62e04bc7d6b629d64d44712/examples/smbexec.py#L286-L296
  - https://github.com/fortra/impacket/blob/edef71f17bc1240f9f8c957bbda98662951ac3ec/examples/smbexec.py#L60
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/builtin/system/service_control_manager/win_system_hack_smbexec.yml
author: Omer Faruk Celik, Huntrule Team
date: 2018-03-20
modified: 2023-11-09
tags:
  - attack.lateral-movement
  - attack.execution
  - attack.t1021.002
  - attack.t1569.002
logsource:
  product: windows
  service: system
detection:
  selection_eid:
    Provider_Name: Service Control Manager
    EventID: 7045
  selection_service_name:
    ServiceName: BTOBTO
  selection_service_image:
    ImagePath|contains:
      - ".bat & del "
      - __output 2^>^&1 >
  condition: selection_eid and 1 of selection_service_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1
related:
  - id: 52a85084-6989-40c3-8f32-091e12e13f09
    type: derived

What it detects

This rule identifies Windows service creation events (EventID 7045) where the Service Control Manager creates a specific service name and the service image path contains command-line patterns consistent with smbexec.py-style remote execution and cleanup. Attackers may use this technique to run commands on remote Windows hosts via a newly installed service, enabling lateral movement and execution while leaving minimal artifacts. It relies on Windows System telemetry from the Service Control Manager, specifically EventID 7045 with matching ServiceName and ImagePath content.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.