name: Services LOLBAS Execution Process Spawn id: ba9e1954-4c04-11ec-8b74-3e22fbd008af version: 1 date: '2021-11-22' author: Mauricio Velazco, Splunk status: production type: TTP description: The following analytic identifies `services.exe` spawning a LOLBAS execution process. When adversaries execute code on remote endpoints abusing the Service Control Manager and creating a remote malicious service, the executed command is spawned as a child process of `services.exe`. The LOLBAS project documents Windows native binaries that can be abused by threat actors to perform tasks like executing malicious code. Looking for child processes of services.exe that are part of the LOLBAS project can help defenders identify lateral movement activity. data_source: - Sysmon Event ID 1 search: selection1: Image|endswith: - Regsvcs.exe - Ftp.exe - OfflineScannerShell.exe - Rasautou.exe - Schtasks.exe - Xwizard.exe - Dllhost.exe - Pnputil.exe - Atbroker.exe - Pcwrun.exe - Ttdinject.exe - Mshta.exe - Bitsadmin.exe - Certoc.exe - Ieexec.exe - Microsoft.Workflow.Compiler.exe - Runscripthelper.exe - Forfiles.exe - Msbuild.exe - Register-cimprovider.exe - Tttracer.exe - Ie4uinit.exe - Bash.exe - Hh.exe - SettingSyncHost.exe - Cmstp.exe - Mmc.exe - Stordiag.exe - Scriptrunner.exe - Odbcconf.exe - Extexport.exe - Msdt.exe - WorkFolders.exe - Diskshadow.exe - Mavinject.exe - Regasm.exe - Gpscript.exe - Rundll32.exe - Regsvr32.exe - Msiexec.exe - Wuauclt.exe - Presentationhost.exe - Wmic.exe - Runonce.exe - Syncappvpublishingserver.exe - Verclsid.exe - Infdefaultinstall.exe - Explorer.exe - Installutil.exe - Netsh.exe - Wab.exe - Dnscmd.exe - At.exe - Pcalua.exe - Msconfig.exe ParentImage: services.exe condition: (selection1) how_to_implement: To successfully implement this search, you need to be ingesting logs with the process name, parent process, and command-line executions from your endpoints. known_false_positives: Legitimate applications may trigger this behavior, filter as needed. references: - https://attack.mitre.org/techniques/T1543/003/ - https://pentestlab.blog/2020/07/21/lateral-movement-services/ - https://lolbas-project.github.io/ tags: analytic_story: - Active Directory Lateral Movement - Living Off The Land - Qakbot asset_type: Endpoint confidence: 60 impact: 90 message: Services.exe spawned a LOLBAS process on $dest mitre_attack_id: - T1543 - T1543.003 observable: - name: dest type: Endpoint role: - Victim product: - Splunk Enterprise - Splunk Enterprise Security - Splunk Cloud risk_score: 54 security_domain: endpoint tests: - name: True Positive Test attack_data: - data: https://media.githubusercontent.com/media/splunk/attack_data/master/datasets/attack_techniques/T1543.003/lateral_movement_lolbas/windows-sysmon.log source: XmlWinEventLog:Microsoft-Windows-Sysmon/Operational sourcetype: xmlwineventlog