Analytics BIOC
Low
✕
Elevation to SYSTEM via services
Services were affected by a non SYSTEM integrity level process.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Execution (TA0002) Privilege Escalation (TA0004)
ATT&CK techniques: Create or Modify System Process: Windows Service (T1543.003) System Services: Service Execution (T1569.002)
Detector tags: Malicious Service Analytics
Attacker's goals:
Escalate privileges to system and execute commands.
Investigative actions:
Investigate the service being spawned on the host for malicious activities.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Elevation to SYSTEM via service creation Low
- Elevation to SYSTEM via service modification Low