Windows Service Creation for WerFaultSvc Using C:\Windows\WinSxS\WerFault.exe

Alerts on Windows service creation of WerFaultSvc pointing to C:\Windows\WinSxS\...\WerFault.exe.

FreeReviewedSigma · Critical · v5
Product
windows
Service
system
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-05-10
Updated
2026-07-31

What it detects

This rule flags Windows System service creation events where the Service Control Manager registers a service named "WerFaultSvc". The persistence-relevant behavior is the association of that service to an executable path under C:\Windows\WinSxS\ and ending with \WerFault.exe, which is an unusual combination attackers may use to maintain execution. It relies on Windows service control manager telemetry (Event ID 7045) containing the provider name, service name, and image path.

Changelog

v5
  1. v5
    Candidate ingested via manual entry.2026-07-31
  2. v4
    Candidate ingested via manual entry.2026-07-31
  3. v3
    Candidate ingested via manual entry.2026-07-31
  4. v2
    Candidate ingested via manual entry.2026-07-31
  5. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.