Detection: Attempt To Delete Services
Description
The following analytic identifies Windows Service Control, sc.exe
, attempting to delete a service. This is typically identified in parallel with other instances of service enumeration of attempts to stop a service and then delete it. Adversaries utilize this technique to terminate security services or other related services to continue there objective and evade detections.
Annotations
No annotations available.
Implementation
To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. If you are using Sysmon, you must have at least version 6.0.4 of the Sysmon TA.
Known False Positives
It is possible administrative scripts may start/stop/delete services. Filter as needed.
Associated Analytic Story
Risk Based Analytics (RBA)
Risk Message | Risk Score | Impact | Confidence |
---|---|---|---|
An instance of $parent_process_name$ spawning $process_name$ was identified on endpoint $dest_device_id$ by user $dest_user_id$ attempting to delete a service. | 36 | 60 | 60 |
References
-
https://thedfirreport.com/2020/04/20/sqlserver-or-the-miner-in-the-basement/
-
https://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1543.003/T1543.003.md
Version: 6