Hunting Rituals #2: Threat hunting for abuse of Windows Services
ID: 4bdcba65-7c5c-5385-9c9c-a788a2462248
STIX ID: report--4bdcba65-7c5c-5385-9c9c-a788a2462248
Feed Name: Group-IB Blog
This post outlines practical threat hunting methods to detect creation and abuse of Windows services for persistence (MITRE ATT&CK T1543.003), emphasizing two telemetry-driven hypotheses: process-based detection of service creation (e.g., sc.exe with the create parameter) and registry-based detection of service installs/modifications under HKLM\SYSTEM\ControlSet001\services via ImagePath and ServiceDll. It details hunting workflows for both EXE- and DLL-backed services (DLLs via svchost.exe with reg.exe edits), highlights trade-offs between fidelity and noise, and provides example EDR queries to operationalize these detections.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
