Hide Navigation Hide TOC PowerShell as a Service in Registry (4a5f5a5e-ac01-474b-9b4e-d61298c9df1d) Detects that a powershell code is written to the registry as a service. Cluster A Galaxy A Cluster B Galaxy B Level PowerShell as a Service in Registry (4a5f5a5e-ac01-474b-9b4e-d61298c9df1d) Sigma-Rules Service Execution - T1569.002 (f1951e8a-500e-4a26-8803-76d95c4554b4) Attack Pattern 1 System Services - T1569 (d157f9d2-d09a-4efa-bb2a-64963f94e253) Attack Pattern Service Execution - T1569.002 (f1951e8a-500e-4a26-8803-76d95c4554b4) Attack Pattern 2