kevmap

TechniquesT1543.003 › AN1527

AN1527 Analytic 1527

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects creation or modification of Windows Services through command-line tools (e.g., sc.exe, powershell.exe), Registry key changes under HKLM\System\CurrentControlSet\Services, and service execution under SYSTEM with unsigned or anomalous binary paths. Detects privilege escalation via driver installation or CreateServiceW usage. Correlates parent-child lineage, startup behavior, and rare service names.</p>
Detects
T1543.003 Windows Service
Part of
DET0552 Detection of Windows Service Creation or Modification

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SecurityEventCode=4697DC0060 Service Creation
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:SysmonEventCode=13, 14DC0063 Windows Registry Key Modification
WinEventLog:SysmonEventCode=6DC0079 Driver Load

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ServiceNamePatternRegex for suspicious or uncommon service names (e.g., `svhostx`, `winhelp`, etc.)
ImagePathFilterFlag services whose image path resides in uncommon directories (e.g., `C:\Users\`, `C:\Temp\`)
DriverExtensionListWatch for `.sys` files loaded by `sc`, Registry, or `ZwLoadDriver` APIs
StartupTypeChangeWindowTemporal window to correlate Registry `Start` key changes with service creation
UnsignedBinaryAlertRaise alerts for unsigned binaries registered as services