Windows System Service Creation for Scheduled Scan and UpdatMachine
Alerts on Windows service installation events for persistence-related scheduled services named SC Scheduled Scan or UpdatMachine.
FreeUnreviewedSigmacriticalv1
windows-system-service-creation-for-scheduled-scan-and-updatmachine-53ba33fd
title: Windows System Service Creation for Scheduled Scan and UpdatMachine
id: e3a373a7-3515-4605-8abf-07f4fd084957
related:
- id: c0580559-a6bd-4ef6-b9b7-83703d98b561
type: similar
- id: 7bdf2a7c-3acc-4091-9581-0a77dad1c5b5
type: similar
- id: ce6e34ca-966d-41c9-8d93-5b06c8b97a06
type: similar
- id: 53ba33fd-3a50-4468-a5ef-c583635cfa92
type: derived
status: test
description: This rule flags Windows System events where the Service Control Manager creates services named "SC Scheduled Scan" or "UpdatMachine". Creating or modifying scheduled services can provide persistence by running attacker-chosen executables or scripts on a schedule. It relies on Windows System telemetry from Event ID 7045, which logs service installation details including the provider and service name.
references:
- https://web.archive.org/web/20180402134442/https://nyotron.com/wp-content/uploads/2018/03/Nyotron-OilRig-Malware-Report-March-2018C.pdf
- https://github.com/SigmaHQ/sigma/blob/master/rules-emerging-threats/2018/TA/OilRig/win_system_apt_oilrig_mar18.yml
author: Florian Roth (Nextron Systems), Markus Neis, Jonhnathan Ribeiro, Daniil Yugoslavskiy, oscd.community, Huntrule Team
date: 2018-03-23
modified: 2023-03-08
tags:
- attack.privilege-escalation
- attack.execution
- attack.persistence
- attack.defense-impairment
- attack.g0049
- attack.t1053.005
- attack.s0111
- attack.t1543.003
- attack.t1112
- attack.command-and-control
- attack.t1071.004
- detection.emerging-threats
logsource:
product: windows
service: system
detection:
selection:
Provider_Name: Service Control Manager
EventID: 7045
ServiceName:
- SC Scheduled Scan
- UpdatMachine
condition: selection
falsepositives:
- Unlikely
level: critical
license: DRL-1.1
What it detects
This rule flags Windows System events where the Service Control Manager creates services named "SC Scheduled Scan" or "UpdatMachine". Creating or modifying scheduled services can provide persistence by running attacker-chosen executables or scripts on a schedule. It relies on Windows System telemetry from Event ID 7045, which logs service installation details including the provider and service name.
Known false positives
- Unlikely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.