Known service display name with uncommon image-path
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Malicious Service Analytics
ATT&CK Tactic
Persistence (TA0003), Execution (TA0002)
ATT&CK Technique
Create or Modify System Process: Windows Service (T1543.003), System Services: Service Execution (T1569.002)
Severity
Low
Description
Service created with a known display name but has an uncommon image-path.
Attacker's Goals
Run malicious code with seemingly trustworthy services.
Investigative actions
Investigate the image path of the newly created service.
Investigate the causality actor process that initiated the activity.
Variations
Was this helpful?
