Known service name with an uncommon image-path
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent with eXtended Threat Hunting (XTH)
Detector Tags
Malicious Service Analytics
ATT&CK Tactic
Persistence (TA0003), Execution (TA0002)
ATT&CK Technique
Create or Modify System Process: Windows Service (T1543.003), System Services: Service Execution (T1569.002)
Severity
Low
Description
A Service with a known service name has an uncommon image-path.
Attacker's Goals
Run malicious code within seemingly trustworthy services.
Investigative actions
Investigate the image-path of the newly created service.
Investigate the causality actor process that initiated the activity.
Variations
PreviousKnown service display name with uncommon image-path
NextKubelet server communication from a pod
Was this helpful?
