Files
splunk-security_content/lookups/csv/windows_suspicious_services.csv

18 KiB

1service_nameservice_pathtool_nametool_categorytool_typeseveritycommentreference
2*mimidrv*mimidrvCredential Accessoffensive_toolcriticalhttps://github.com/mthcht/awesome-lists
3*mimikatz*mimidrvCredential Accessoffensive_toolcriticalhttps://github.com/mthcht/awesome-lists
4*sharpsploit*sharpsploitLateral Movementoffensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/SharpSploit.csvhttps://github.com/cobbr/SharpSploit/blob/c16931ddb8cd2335e0bd26feb9aaa35f449d48db/SharpSploit/LateralMovement/SCM.cs#L209
53proxy3proxyDefense Evasionoffensive_toolmediumhttps://github.com/3proxy/3proxy/blob/a80bef9ecf0c0ed98ccb1a1a764f6b79a620b78f/src/stringtable.c#L14https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/_Others/3proxy.csv
6AADInternalsAADInternalsCredential Accessgreyware_toolshighA little service to steal the AD FS DKM secrethttps://github.com/Gerenios/AADInternals/blob/0fa2edf5676439cd3fe7c92ed8006b63f0be9632/ADFS.ps1#L484C132-L484C144
7aswSP_ArPot1killProcessPOCDefense Evasionoffensive_toolhighabused by MONTI ransomwarehttps://github.com/timwhitez/killProcessPOC - https://github.com/mthcht/ThreatHunting-Keywords/tree/main/tools/I-K/killProcessPOC.csv - https://www.withsecure.com/content/dam/with-secure/en/resources/WS_Professionalisation_of_CyberCrime_EN.pdf
8aswSP_ArPot2killProcessPOCDefense Evasionoffensive_toolhighabused by MONTI ransomwarehttps://github.com/timwhitez/killProcessPOC - https://github.com/mthcht/ThreatHunting-Keywords/tree/main/tools/I-K/killProcessPOC.csv - https://www.withsecure.com/content/dam/with-secure/en/resources/WS_Professionalisation_of_CyberCrime_EN.pdf
9aswSP_ArPot3killProcessPOCDefense Evasionoffensive_toolhighabused by MONTI ransomwarehttps://github.com/timwhitez/killProcessPOC - https://github.com/mthcht/ThreatHunting-Keywords/tree/main/tools/I-K/killProcessPOC.csv - https://www.withsecure.com/content/dam/with-secure/en/resources/WS_Professionalisation_of_CyberCrime_EN.pdf
10aswSP_ArPotskillProcessPOCDefense Evasionoffensive_toolhighabused by MONTI ransomwarehttps://github.com/timwhitez/killProcessPOC - https://github.com/mthcht/ThreatHunting-Keywords/tree/main/tools/I-K/killProcessPOC.csv - https://www.withsecure.com/content/dam/with-secure/en/resources/WS_Professionalisation_of_CyberCrime_EN.pdf
11SecurityCenterIBMClop RansomwareDefense Evasionoffensive_toolhighabused by Clop ransomwarehttps://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html
12WinCheckDRVsClop RansomwareDefense Evasionoffensive_toolhighabused by Clop ransomwarehttps://blog.virustotal.com/2020/11/keep-your-friends-close-keep-ransomware.html
13BadWindowsServiceBadWindowsServicePrivilege Escalationoffensive_toolcriticalhttps://github.com/eladshamir/BadWindowsService/blob/a7057720763fceaa7cbac9088d4c69b43d17a28f/BadWindowsService/ProjectInstaller.Designer.cs#L44https://github.com/mthcht/ThreatHunting-Keywords/tree/main/tools/A-C/BadWindowsService.csv
14BlockNewProcBlockNewProcDefense Evasionoffensive_toolcriticalPoCs to block new process with Process Notify Callback method - BlockNewProchttps://github.com/daem0nc0re/VectorKernel/blob/main/BlockNewProc/README.md
15BTOBTOsmbExecLateral Movementoffensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/I-K/impacket.csv
16c3pool_minerxmrigCryptominergreyware_toolcriticalhttps://github.com/C3Pool/xmrig_setup/blob/82c4e9bf7ee3c0c9cd925ede6e46e9ed4cc5f195/setup_c3pool_miner.bat#L380https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/X-Z/xmrig.csv
17chopperTChopperLateral Movementoffensive_toolcriticalhttps://github.com/lawrenceamer/TChopper/blob/f7383a36af813019ebefb70803dc82a842ed9273/chopper.lpr#L237C25-L237C34https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/Tchopper.csv
18CorpVPNUacMePersistenceoffensive_toolcriticalhttps://github.com/r00t-3xp10it/redpill/blob/611d39b8bff717ac84d58550dc04e1b312acb19e/bin/UacMe.ps1#L291https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/redpill.csv
19CreateTokenCreateTokenPrivilege Escalationoffensive_toolcriticalPoCs to get full privileged SYSTEM token with `ZwCreateToken()` API - CreateTokenhttps://github.com/daem0nc0re/VectorKernel/blob/main/CreateToken/README.md
20CreatSvcRpc_*CreateSvcRpcPrivilege Escalationoffensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/SspiUacBypass.csv
21csexecsvccsexecLateral Movementoffensive_toolcriticalhttps://github.com/malcomvetter/CSExec/blob/d6bd3f97e66dc65ccf64d9102a33379fdb769614/csexecsvc/Program.cs#L13https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/A-C/csexec.csv
22CyberGhost 6 ServiceCyberGhostVPNVPNgreyware_toolhighhttps://www.cyberghostvpn.com/https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/A-C/CyberGhost%20VPN.csv
23CyberGhost 7 ServiceCyberGhostVPNVPNgreyware_toolhighhttps://www.cyberghostvpn.com/https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/A-C/CyberGhost%20VPN.csv
24CyberGhost 8 ServiceCyberGhostVPNVPNgreyware_toolhighhttps://www.cyberghostvpn.com/https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/A-C/CyberGhost%20VPN.csv
25CyberGhost Tunnel Client: CyberGhost-WireGuard-1CyberGhostVPNVPNgreyware_toolhighhttps://www.cyberghostvpn.com/https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/A-C/CyberGhost%20VPN.csv
26CyberGhost6ServiceCyberGhostVPNVPNgreyware_toolhighhttps://www.cyberghostvpn.com/ - command: C:\Program Files\CyberGhost 6\Dashboard.Service.exehttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/A-C/CyberGhost%20VPN.csv
27CyberGhost7ServiceCyberGhostVPNVPNgreyware_toolhighhttps://www.cyberghostvpn.com/ - command: C:\Program Files\CyberGhost 7\Dashboard.Service.exehttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/A-C/CyberGhost%20VPN.csv
28CyberGhost8ServiceCyberGhostVPNVPNgreyware_toolhighhttps://www.cyberghostvpn.com/ - command: C:\Program Files\CyberGhost 8\Dashboard.Service.exehttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/A-C/CyberGhost%20VPN.csv
29CyberGhostTunnel$CyberGhost-WireGuard-1CyberGhostVPNVPNgreyware_toolhighhttps://www.cyberghostvpn.com/ - command: \Program Files\CyberGhost 8\Applications\VPN\WGHelper.exe /service C:\Windows\system32\config\systemprofile\AppData\Local\CyberGhost\WGSession-1\CyberGhost-WireGuard-1.confhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/A-C/CyberGhost%20VPN.csv
30dcryptDiskCryptorImpactoffensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/D-F/DiskCryptor.csv
31dnsproxydns-proxyDefense Evasionoffensive_toolcriticaldnsproxy servicehttps://github.com/AdguardTeam/dnsproxy/pull/194/files
32final_segTChopperLateral Movementoffensive_toolcriticalhttps://github.com/lawrenceamer/TChopper/blob/f7383a36af813019ebefb70803dc82a842ed9273/chopper.lpr#L237C25-L237C34https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/Tchopper.csv
33GetFullPrivsGetFullPrivsPrivilege Escalationoffensive_toolcriticalPoCs to get full privileges with DKOM method - GetFullPrivshttps://github.com/daem0nc0re/VectorKernel/blob/main/GetFullPrivs/README.md
34GetProcHandleGetProcHandlePrivilege Escalationoffensive_toolcriticalPoCs to get full access process handle from kernelmode - GetProcHandlehttps://github.com/daem0nc0re/VectorKernel/blob/main/GetProcHandle/README.md
35GoodSync ServergoodyncData Exfiltrationgreyware_toolhighhttps://www.goodsync.com/
36InjectLibraryInjectLibraryDefense Evasionoffensive_toolcriticalPoCs to perform DLL injection with Kernel APC Injection method - InjectLibraryhttps://github.com/daem0nc0re/VectorKernel/blob/main/InjectLibrary/README.md
37KrbSCMKrbRelayUpPrivilege Escalationoffensive_toolcriticalhttps://github.com/Dec0ne/KrbRelayUp/blob/e919f78afbacdb2c2e86f17267674069a377011c/README.md?plain=1#L90https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/I-K/KrbRelayUp.csv
38MagnetRAMCapture DriverMAGNET RAM CaptureCredential Accessgreyware_toolcriticalhttps://startupstash.com/tools/magnet-ram-capture/
39maintimpacketremoteshellLateral Movementoffensive_toolhighdefault service name installed https://github.com/trustedsec/The_Shelf/blob/feaece2bf00ba0ff46b39cadbd06803be1114d7a/POC/impacketremoteshell/RemoteMaint/main.cpp#L108https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/impacketremoteshell.csv
40MakeMeAdminMakeMeAdminPrivilege Escalationoffensive_toolhighEnables users to elevate themselves to administrator-level rights https://github.com/pseymour/MakeMeAdmin/blob/18ea04be3dbc6e7cab8096558a3b02ef8f8682f6/Service/ProjectInstaller.Designer.cs#L63https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/L-N/MakeMeAdmin.csv
41MeterpretermetasploitC2offensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/L-N/metasploit.csv
42metsvcmetsvc-server.exeMetasploit serverExploitationoffensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/L-N/metasploit.csv
43ModHideModHideDefense Evasionoffensive_toolcriticalPoCs to hide loaded kernel drivers with DKOM method - ModHidehttps://github.com/daem0nc0re/VectorKernel/blob/main/ModHide/README.md
44Neo_VPN*\System32\drivers\Neo6_x64_VPN.sysSoftEtherVPNDefense Evasiongreyware_toolmediumhttps://github.com/SoftEtherVPN/SoftEtherVPNhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/SoftEtherVPN.csv
45NoRebootSvcNoReboot.exePSBits NoReboot.coffensive_toolhighhttps://github.com/gtworek/PSBits/blob/master/NoRebootSvc/readme.md
46Npcap Packet Driver (NPCAP)NpCap Windows Packet Capture Library & DriverCollectiongreyware_toollowhttps://github.com/nmap/npcap
47PAExecpaexecLateral Movementoffensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/O-Q/PAExec.csv
48PAExec-*paexecLateral Movementoffensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/O-Q/PAExec.csv
49PCHunter*PCHunterDefense Evasiongreyware_toolmediumPCHunter service name installation - https://www.majorgeeks.com/files/details/pc_hunter.htmlhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/O-Q/PCHunter.csv
50physmem2profitphysmem2profitCredential Accessoffensive_toolcriticalhttps://github.com/WithSecureLabs/physmem2profit/blob/2f64133bd9931303b8ae47630835e96347e0f294/server/Plugins/WinPmem.cs#L11https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/O-Q/physmem2profit.csv
51PowerUpServicePowerSploit Privesc.tests.ps1Privilege Escalationoffensive_toolcriticalhttps://github.com/PowerShellMafia/PowerSploit/blob/master/Tests/Privesc.tests.ps1
52PPLBladepplbladeDefense Evasionoffensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/O-Q/PPLBlade.csv
53ProcExpDriverDumpPersistenceoffensive_toolcriticalThis program configures and loads a Windows service to manage a driver https://github.com/trustedsec/The_Shelf/blob/feaece2bf00ba0ff46b39cadbd06803be1114d7a/POC/driverdump/DriverDump/DriverDump.c#L45https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/D-F/DriverDump.csv
54ProcHideProcHideDefense Evasionoffensive_toolcriticalPoCs to hide process with DKOM method - ProcHidehttps://github.com/daem0nc0re/VectorKernel/blob/main/ProcHide/README.md
55ProcProtectProcProtectDefense Evasionoffensive_toolcriticalPoCs to manipulate Protected Process - ProcProtecthttps://github.com/daem0nc0re/VectorKernel/blob/main/ProcProtect/README.md
56pwdump*PWDumpXCredential Accessoffensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/O-Q/pwdump.csv
57PWDumpX ServicePWDumpXCredential Accessoffensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/O-Q/PWDumpX.csv
58QueryModuleQueryModuleCollectionoffensive_toolmediumPoCs to perform retrieving kernel driver loaded address information - QueryModulehttps://github.com/daem0nc0re/VectorKernel/blob/main/QueryModule/README.md
59RandomServiceInvoke-SMBRemotingLateral Movementoffensive_toolcriticalInvoke-SMBRemoting service examplehttps://github.com/Leo4j/Amnesiac/blob/216ba3a280bf49ea3f5b1afab80f843bbde3548d/Tools/Invoke-SMBRemoting.ps1#L33C99-L33C113
60RemCom ServiceRemCom.exeLateral movementoffensive_toolcriticalhttps://github.com/kavika13/RemCom
61REPLACE_ME_DummyServiceNamenetexecCredential Accessoffensive_toolcriticalhttps://github.com/Pennyw0rth/NetExec/blob/b855dac2b696ea1b744f10a0573c6b394670a5cb/nxc/data/keepass_trigger_module/RestartKeePass.ps1#L4https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/L-N/NetExec.csv
62Ring0NamedPipeFilterNamedPipeMasterPrivilege Escalationoffensive_toolcriticalhttps://github.com/gavz/NamedPipeMasterhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/L-N/NamedPipeMaster.csv
63Service_*PsMapExecLateral Movementoffensive_toolcriticalPsMapExec creating services regex detection: Service_[A-Za-z]{16}https://github.com/The-Viper-One/PsMapExec/blob/0ae7a6967c07bf3ebf555e665d4c43ce86c6addf/PsMapExec.ps1#L1488
64sesshijackatomic-red-team test T1563.002Persistenceoffensive_toolhighhttps://github.com/redcanaryco/atomic-red-team/blob/master/atomics/T1563.002/T1563.002.md?plain=1
65SEVPNCLIENTDEV*\Program Files\SoftEther VPN Client Developer Edition\vpnclient.exe*SoftEtherVPNDefense Evasiongreyware_toolmediumhttps://github.com/SoftEtherVPN/SoftEtherVPNhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/SoftEtherVPN.csv
66Shadowsocks Local ServiceShadowsocksC2greyware_toolhighhttps://github.com/shadowsocks/shadowsocks-rust/blob/846752866e0b52c3d93efa2036204eadc36cc696/README.md?plain=1#L458https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/shadowsocks.csv
67shadowsocks-local-serviceShadowsocksC2greyware_toolhighhttps://github.com/shadowsocks/shadowsocks-rust/blob/846752866e0b52c3d93efa2036204eadc36cc696/README.md?plain=1#L458https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/shadowsocks.csv
68SilkServiceSilkETWDiscoverygreyware_toollowC# wrappers for ETW - meant to abstract away the complexities of ETW and give people a simple interface to perform research and introspectionhttps://github.com/mandiant/SilkETW
69sliver*sliverC2offensive_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/sliver.csv
70SoftEther VPN*SoftEtherVPNDefense Evasiongreyware_toolmediumhttps://github.com/SoftEtherVPN/SoftEtherVPNhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/SoftEtherVPN.csv
71StealTokenStealTokenCredential Accessoffensive_toolcriticalPoCs to perform token stealing from kernelmode - StealTokenhttps://github.com/daem0nc0re/VectorKernel/blob/main/CreateToken/README.md
72svcEasySystemp0wnedShellPrivilege Escalationoffensive_toolcriticalhttps://github.com/Cn33liz/p0wnedShell/blob/35853bcc2a184f0e0fa7b18b0e54d4ad7a985ed6/p0wnedShell/Modules/PrivEsc/p0wnedEasySystem.cs#L582C33-L582C46https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/O-Q/p0wnedShell.csv
73svcHighPrivEasySystemPrivilege Escalationoffensive_toolcriticalhttps://github.com/S3cur3Th1sSh1t/Creds/blob/f71e780c51fdc2fdabe4e51831fa6289b1bede96/Csharp/NamedPipeSystem.cs#L28https://github.com/mthcht/awesome-lists
74TestServiceSharpyStay defaultPersistenceoffensive_toolcriticalhttps://github.com/antonioCoco/SharPyShell/blob/29718225791f11fd3d66dd03df4c05c414256630/modules/ps_modules/Get-System.ps1#L89
75TestSVCSharpyShell - Get-System.ps1 default service namePrivilege Escalationoffensive_toolcriticalhttps://github.com/antonioCoco/SharPyShell/blob/29718225791f11fd3d66dd03df4c05c414256630/modules/ps_modules/Get-System.ps1#L89
76UACBypassedServiceS4UTomato & KRBUACBypassPrivilege Escalationoffensive_toolcriticalhttps://github.com/wh0amitz/S4UTomato/blob/c709a2997efb1b30375c5134ff57eb49ec177918/S4UTomato/lib/KrbSCM.cs#L10 - https://github.com/wh0amitz/KRBUACBypass/blob/e2ad3ff8b5810dda0b2d75442f1c67aef7e3c4c1/KRBUACBypass/lib/KrbSCM.cs#L10https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/S4UTomato.csv
77VPN Client Device Driver - VPNSoftEtherVPNDefense Evasiongreyware_toolmediumhttps://github.com/SoftEtherVPN/SoftEtherVPNhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/SoftEtherVPN.csv
78WCESERVICEwceLateral Movementgreyware_toolhighhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/U-W/wce.csv
79windows_monitoringsocial-engineer-toolkit persistence payloadPersistenceoffensive_toolhighhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/R-T/social-engineer-toolkit.csv
80winexesvcwinexeLateral Movementgreyware_toollowhttps://www.kali.org/tools/winexehttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/U-W/winexe.csv
81WinPwnageWinPwnagePersistenceoffensive_toolcriticalhttps://github.com/rootm0s/WinPwnage/blob/aed0389b4d20b61e3c6de611a3386d3e3fbcae01/winpwnage/functions/persist/persistMethod12.py#L24https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/U-W/WinPwnage.csv
82WinPwnageVPNWinPwnagePersistenceoffensive_toolcriticalhttps://github.com/rootm0s/WinPwnage/blob/aed0389b4d20b61e3c6de611a3386d3e3fbcae01/winpwnage/functions/uac/uacMethod13.py#L54https://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/U-W/WinPwnage.csv
83WinRing0_*xmrigCryptomininggreyware_toolcriticalhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/X-Z/xmrig.csv
84wsc_proxyno_defenderDefense Evasionoffensive_toollowtechnique observed with the tool no_defender https://github.com/es3n1n/no-defender - subject to false positives if avast is installedhttps://github.com/mthcht/ThreatHunting-Keywords/blob/main/tools/L-N/no_defender.csv