Detection of Unauthorized Security Service Termination on Windows
Adversaries frequently attempt to disable security-related services on Windows endpoints using standard administration tools to facilitate defense evasion and destructive activity.
Adversaries often attempt to terminate security-related services on Windows endpoints as a critical step in their attack lifecycle. By disabling antivirus, endpoint detection and response (EDR), or other security software, threat actors aim to bypass defensive measures to achieve persistence, exfiltration, or data destruction. This activity is frequently observed in high-impact campaigns, including those involving destructive malware like WhisperGate or information stealers such as Trickbot and Azorult.
Defenders can identify this behavior by monitoring for the misuse of built-in administrative tools such as 'sc.exe', 'net.exe', or PowerShell 'Stop-Service' cmdlets directed at known security service names. Because legitimate administrative maintenance may occasionally involve stopping services, this detection is most effective when cross-referenced against a lookup table of security-critical services. Failure to detect this activity can lead to a complete loss of endpoint visibility, allowing an attacker to operate undetected during the later stages of an intrusion.
Attack Chain
- Attacker gains initial access to the Windows endpoint via phishing or exploit.
- Attacker executes discovery commands to identify running security products.
- Attacker identifies the specific service names associated with the security software.
- Attacker launches 'sc.exe', 'net.exe', or PowerShell with administrative privileges.
- Attacker invokes the 'stop' command or 'Stop-Service' cmdlet against the target security service.
- The service is successfully terminated, disabling the defensive telemetry feed.
- Attacker proceeds with follow-on activities such as data wiping or payload installation.
Impact
Successful termination of security services severely undermines the defensive posture of the organization. It renders the endpoint blind to subsequent malicious actions, potentially leading to widespread data destruction, theft of credentials, and full system compromise. This TTP has been observed in attacks targeting critical infrastructure and organizations globally, resulting in significant operational downtime and data loss.
Recommendation
- Deploy the provided Sigma rule to monitor process executions targeting security services.
- Maintain a comprehensive, updated lookup table of authorized security services (e.g., AV daemons, EDR sensors) to filter out legitimate administrative restarts from malicious service termination.
- Ensure that Sysmon Event ID 1 or Windows Event ID 4688 is actively ingested into the SIEM, capturing full command-line arguments.
- Restrict local administrative privileges to reduce the ability of unauthorized users to modify service states.
Immediate actions
Deploy detection rule to identify service termination attempts
Threat Hunt
Search for non-standard parent processes executing service stop commands
Data: Process creation logs with parent process context
Mitigations
Enforce least privilege for service management on endpoints
T1562.001
Detection coverage 1
Detect Attempted Security Service Termination
highDetects the use of sc.exe, net.exe, or PowerShell Stop-Service to stop security-related services
Detection queries are available on the platform. Get full rules →