<<< Hide Navigation Hide TOC >>>
Service Security Descriptor Tampering Via Sc.EXE (98c5aeef-32d5-492f-b174-64a691896d25)
Detection of sc.exe utility adding a new service with special permission which hides that service.
Cluster A![]() |
Galaxy A![]() |
Cluster B![]() |
Galaxy B![]() |
Level![]() |
---|---|---|---|---|
Service Security Descriptor Tampering Via Sc.EXE (98c5aeef-32d5-492f-b174-64a691896d25) | Sigma-Rules | Services Registry Permissions Weakness - T1574.011 (17cc750b-e95b-4d7d-9dde-49e0de24148c) | Attack Pattern | 1 |
Hijack Execution Flow - T1574 (aedfca76-3b30-4866-b2aa-0f1d7fd1e4b6) | Attack Pattern | Services Registry Permissions Weakness - T1574.011 (17cc750b-e95b-4d7d-9dde-49e0de24148c) | Attack Pattern | 2 |