Windows Service Creation for Backdoor Persistence via GoogleUpdate (Event ID 7045)

Flags creation of a "GoogleUpdate" Windows service with rundll32/FileProtocolHandler image path pointing to ProgramData persistence.

FreeReviewedSigma · Critical · v5
Product
windows
Service
system
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-15
Updated
2026-07-31

What it detects

This rule identifies Windows system service creation events (Event ID 7045) where the new service is named "GoogleUpdate" and its binary path includes rundll32, FileProtocolHandler, and a ProgramData-based GoogleUpdate executable. This pattern is used to establish persistence, allowing an attacker-controlled component to run as a Windows service. Detection relies on Windows Service Control Manager telemetry reporting provider name, service name, event ID, and the configured ImagePath details.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.