Suspicious Service DACL Modification Via Set-Service Cmdlet - PS

 Original Source: [Sigma source]
Title: Suspicious Service DACL Modification Via Set-Service Cmdlet - PS
Status: test
Description:Detects usage of the "Set-Service" powershell cmdlet to configure a new SecurityDescriptor that allows a service to be hidden from other utilities such as "sc.exe", "Get-Service"...etc. (Works only in powershell 7)
References:
  -https://twitter.com/Alh4zr3d/status/1580925761996828672
  -https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/set-service?view=powershell-7.2
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-10-24
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.011'
Logsource:
  • product: windows
  • category: ps_script
  • definition: Requirements: Script Block Logging must be enabled
Detection:
  selection_sddl_flag:
    ScriptBlockText|contains:
      -'-SecurityDescriptorSddl '
      -'-sd '

  selection_set_service:
    ScriptBlockText|contains|all:
      -'Set-Service '
      -'D;;'

    ScriptBlockText|contains:
      -';;;IU'
      -';;;SU'
      -';;;BA'
      -';;;SY'
      -';;;WD'

  condition:all of selection_*
Falsepositives:
  -Rare intended use of hidden services
  -Rare FP could occur due to the non linearity of the ScriptBlockText log
Level: high