title: Malicious Service Installations id: 2cfe636e-317a-4bee-9f2c-1066d9f54d1a description: Detects known malicious service installs that only appear in cases of lateral movement, credential dumping and other suspicious activity author: Florian Roth, Daniil Yugoslavskiy, oscd.community (update) date: 2017/03/27 modified: 2021/05/27 tags: - attack.persistence - attack.privilege_escalation - attack.t1003 - attack.t1035 # an old one - attack.t1050 # an old one - car.2013-09-005 - attack.t1543.003 - attack.t1569.002 logsource: product: windows service: system detection: selection: EventID: 7045 malsvc_paexec: ServiceFileName|contains: '\PAExec' malsvc_wannacry: ServiceName: 'mssecsvc2.0' malsvc_persistence: ServiceFileName|contains: 'net user' condition: selection and 1 of malsvc_* falsepositives: - Penetration testing level: critical