logo

Hunting Rituals #2: Threat hunting for abuse of Windows Services

ID: 4bdcba65-7c5c-5385-9c9c-a788a2462248

STIX ID: report--4bdcba65-7c5c-5385-9c9c-a788a2462248

Feed Name: Group-IB Blog

Date Published: 2023-09-20

Date Updated: 2026-04-27

...
...

This post outlines practical threat hunting methods to detect creation and abuse of Windows services for persistence (MITRE ATT&CK T1543.003), emphasizing two telemetry-driven hypotheses: process-based detection of service creation (e.g., sc.exe with the create parameter) and registry-based detection of service installs/modifications under HKLM\SYSTEM\ControlSet001\services via ImagePath and ServiceDll. It details hunting workflows for both EXE- and DLL-backed services (DLLs via svchost.exe with reg.exe edits), highlights trade-offs between fidelity and noise, and provides example EDR queries to operationalize these detections.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.