Allow Service Access Using Security Descriptor Tampering Via Sc.EXE

 Original Source: [Sigma source]
Title: Allow Service Access Using Security Descriptor Tampering Via Sc.EXE
Status: test
Description:Detects suspicious DACL modifications to allow access to a service from a suspicious trustee. This can be used to override access restrictions set by previous ACLs.
References:
  -https://twitter.com/0gtweet/status/1628720819537936386
  -https://itconnect.uw.edu/tools-services-support/it-systems-infrastructure/msinf/other-help/understanding-sddl-syntax/
  -https://learn.microsoft.com/en-us/windows/win32/secauthz/sid-strings
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-02-28
modified:2025-10-22
Tags:
  • -'attack.privilege-escalation'
  • -'attack.persistence'
  • -'attack.t1543.003'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_sc:
Image|endswith:'\sc.exe' OriginalFileName:'sc.exe'   selection_sdset:
    CommandLine|contains|all:
      -'sdset'
      -'A;'

  selection_trustee:
    CommandLine|contains:
      -';IU'
      -';SU'
      -';BA'
      -';SY'
      -';WD'

  filter_optional_hexnode:
    ParentImage: 'C:\Hexnode\Hexnode Agent\Current\HexnodeAgent.exe'
  condition:all of selection_* and not 1 of filter_optional_*
Falsepositives:
  -Unknown
Level: high