Hunting Rituals #2.2: Threat hunting for abuse of Windows Services
ID: 0b3b8ba4-f6c6-5e3a-99e1-118729211f21
STIX ID: report--0b3b8ba4-f6c6-5e3a-99e1-118729211f21
Feed Name: Group-IB Blog
This article provides practical threat hunting guidance for Windows service execution (MITRE ATT&CK T1569.002), detailing hypotheses and EDR-driven methods to detect EXE services spawned by services.exe and DLL services loaded by svchost.exe, along with techniques for baselining, statistical analysis, signature filtering, and investigative pivoting when service installation telemetry is unavailable.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
