Windows Service Creation Indicators for Moriya Rootkit (ZzNetSvc via Service Control Manager)

Alerts on creation of the "ZzNetSvc" service by Service Control Manager (Event ID 7045) on Windows.

FreeReviewedSigma · Critical · v2
Product
windows
Service
system
Author
Bhabesh Raj (SigmaHQ), DRL 1.1
Published
2021-05-06
Updated
2026-07-31

ATT&CK techniques

Persistence → Priv Esc
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Defense Evasion

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule flags a Windows Service Control Manager event where service creation matches the specific service name ZzNetSvc (EventID 7045). Attackers using Moriya-related persistence mechanisms may install or register services to maintain control on a system. The detection relies on Windows System telemetry for service creation events reported by the Service Control Manager, capturing the service name and event details.

Related detections9 linkedT1543.003 — drag to rearrange
Suspicious Service DLL Hijack of IKEEXT or PrintNotify
Service Hiding via SC Sdset Security Descriptor Modification
Malicious Service DLL Hijack for Persistence via Lotus Blossom
Malicious TinyTurla ServiceDll Registration via svchost Group (via registry_set)
Suspicious ToyMaker LAGTOY Service Creation Masquerading as WmiPrvSV via sc.exe
Malicious Service Creation With Autostart binPath via sc.exe (via process_creation)
Malicious svchost Service Creation for TinyTurla Persistence (via process_creation)
Malicious Service Creation Masquerading as nslookup (via process_creation)
Interactive Service Creation Executing cmd via sc.exe
Windows Service Creation Indicators for Moriya Rootkit (ZzNetSvc via Service Control Manager)
Pivot detection · T1543.003 · 9 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.