logo

Hunting Rituals #2.2: Threat hunting for abuse of Windows Services

ID: 0b3b8ba4-f6c6-5e3a-99e1-118729211f21

STIX ID: report--0b3b8ba4-f6c6-5e3a-99e1-118729211f21

Feed Name: Group-IB Blog

Date Published: 2023-11-22

Date Updated: 2026-04-27

...
...

This article provides practical threat hunting guidance for Windows service execution (MITRE ATT&CK T1569.002), detailing hypotheses and EDR-driven methods to detect EXE services spawned by services.exe and DLL services loaded by svchost.exe, along with techniques for baselining, statistical analysis, signature filtering, and investigative pivoting when service installation telemetry is unavailable.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.