Commonly abused process launched as a system service
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Execution (TA0002)
ATT&CK Technique
System Services: Service Execution (T1569.002)
Severity
Informational
Description
This commonly abused host process has been launched by a services.exe parent, indicating it has been installed as a system service. This behavior can have legitimate uses, but often used by malware as a persistence mechanism.
Attacker's Goals
Attackers may use services to persist or execute commands on remote hosts.
Investigative actions
Check whether additional malicious commands were executed from the same process.
Verify if the command-line seems suspicious or contains malicious indicators.
PreviousCommonly abused AutoIT script drops an executable file to disk
NextCompressing data using python
Was this helpful?
