Analytics BIOC
Low
✕
Rare service DLL was added to the registry
A service was added as a dll, which will be executed by svchost.exe. This is a stealthy technique attackers use to persist their malware.
- Module:
- Platform Analytics
- Data source:
- XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005) Persistence (TA0003)
ATT&CK techniques: Masquerading: Masquerade Task or Service (T1036.004) Create or Modify System Process: Windows Service (T1543.003)
Detector tags: Malicious Service Analytics
Attacker's goals:
Masquerade execution on the host using a benign Windows process and achieve persistence.
Investigative actions:
Investigate the suspicious DLL and check for malicious content. Go to the service registry key and investigate it to find the associated executable that runs the service. Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- Rare service DLL was added to the registry from an injected thread Medium (parent: Low)
- Rare service DLL was added to the registry from a rare unsigned actor process High (parent: Low)