BIOC
Informational
✕
New service created via command line
Attackers may leverage services to gain persistence on an endpoint.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Persistence
- Status:
- Enabled
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Create or Modify System Process: Windows Service (T1543.003)
Indicator:
Process action type = execution AND target process cmd = *create*binpath* AND target process name = sc.exe
Preventable: yes