Abuse of Service Permissions to Hide Services Via Set-Service

 Original Source: [Sigma source]
Title: Abuse of Service Permissions to Hide Services Via Set-Service
Status: test
Description:Detects usage of the "Set-Service" powershell cmdlet to configure a new SecurityDescriptor that allows a service to be hidden from other utilities such as "sc.exe", "Get-Service"...etc. (Works only in powershell 7)
References:
  -https://twitter.com/Alh4zr3d/status/1580925761996828672
  -https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.management/set-service?view=powershell-7.2
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-10-17
modified:None
Tags:
  • -'attack.persistence'
  • -'attack.privilege-escalation'
  • -'attack.execution'
  • -'attack.stealth'
  • -'attack.t1574.011'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\pwsh.exe' OriginalFileName:'pwsh.dll'   selection_sddl:
    CommandLine|contains|all:
      -'Set-Service '
      -'DCLCWPDTSD'

  selection_cmdlet:
    CommandLine|contains:
      -'-SecurityDescriptorSddl '
      -'-sd '

  condition:all of selection_*
Falsepositives:
  -Rare intended use of hidden services
Level: high