Elevation to SYSTEM via services
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Malicious Service Analytics
ATT&CK Tactic
Execution (TA0002), Privilege Escalation (TA0004)
ATT&CK Technique
Create or Modify System Process: Windows Service (T1543.003), System Services: Service Execution (T1569.002)
Severity
Low
Description
Services were affected by a non SYSTEM integrity level process.
Attacker's Goals
Escalate privileges to system and execute commands.
Investigative actions
Investigate the service being spawned on the host for malicious activities.
Variations
PreviousEC2 instance Amazon machine image was created
NextEmail attachment(s) with potentially malicious MIME type
Was this helpful?
