Analytics BIOC
Low
✕
Known service display name with uncommon image-path
Service created with a known display name but has an uncommon image-path.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Execution (TA0002)
ATT&CK techniques: Create or Modify System Process: Windows Service (T1543.003) System Services: Service Execution (T1569.002)
Detector tags: Malicious Service Analytics
Attacker's goals:
Run malicious code with seemingly trustworthy services.
Investigative actions:
Investigate the image path of the newly created service. Investigate the causality actor process that initiated the activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
3 variations:
- Known service display name with uncommon image-path created by an untrusted CGO Medium (parent: Low)
- Known Palo Alto service display name with uncommon image-path Medium (parent: Low)
- Known service display name with uncommon image-path in a suspicious folder Medium (parent: Low)