BIOC
Informational
✕
Manipulation of service imagepath configuration
This key specifies the location of the executable file for the driver or service. Malicious executables might be installed in these paths.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Create or Modify System Process: Windows Service (T1543.003) Hijack Execution Flow: Services Registry Permissions Weakness (T1574.011)
Indicator:
Registry action type = create_registry_key , set_registry_value AND registry key name = *\services\*\imagepath Host host os = windows
Preventable: yes