Windows Security Event 4697: HybridConnectionManager Service Installation

Alerts on HybridConnectionManager service installation on Windows via Security Event ID 4697.

FreeReviewedSigma · High · v2
Product
windows
Service
security
Author
Roberto Rodriguez (Cyb3rWard0g), OTR (Open Threat Research) (SigmaHQ), DRL 1.1
Published
2021-04-12
Updated
2026-07-31

ATT&CK techniques

Persistence
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Priv Esc

  6. Defense Evasion

  7. Cred Access

  8. Discovery

  9. Lateral Movement

  10. Collection

  11. C2

  12. Exfiltration

  13. Impact

What it detects

This rule identifies installation attempts of the Windows service named HybridConnectionManager by matching Security Event ID 4697 with the service name and executable filename containing HybridConnectionManager. Attackers may use service installation for persistence or to run attacker-controlled components as a Windows service. It relies on Security audit telemetry for service installation events (EventID 4697) that include service name and service file path details.

Related detections8 linkedT1554 — drag to rearrange
Malicious Backdoored liblzma XZ Utils Library File via file_event
Suspicious Root Filesystem Remount as Writable on Appliance via Mount (via process_creation)
Malicious Backdoored liblzma Loaded by sshd (CVE-2024-3094)
Windows TanStack Supply-Chain File Creation Indicators via router_init.js and router_runtime.js
Linux setcap sets cap_setgid on binaries (Setgid capability assignment)
Linux setcap sets cap_setuid on a binary via setcap utility
Azure Hybrid Connection Manager DNS Queries for servicebus.windows.net (Windows)
Windows Hybrid Connection Manager Service Activity (Event IDs 40300-40302)
Windows Security Event 4697: HybridConnectionManager Service Installation
Pivot detection · T1554 · 8 related

Changelog

v2
  1. v2
    Candidate ingested via manual entry.2026-07-31
  2. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.