Analytics BIOC Low

Known service name with an uncommon image-path

A Service with a known service name has an uncommon image-path.

Module:
Platform Analytics
Data source:
XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003) Execution (TA0002)
ATT&CK techniques: Create or Modify System Process: Windows Service (T1543.003) System Services: Service Execution (T1569.002)
Detector tags: Malicious Service Analytics
Attacker's goals:

Run malicious code within seemingly trustworthy services.

Investigative actions:

Investigate the image-path of the newly created service. Investigate the causality actor process that initiated the activity.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • Known Palo Alto service name with an uncommon image-path Medium (parent: Low)
  • Known service name with an uncommon image-path in a suspicious folder Medium (parent: Low)