Product
high
advisory
Windows Service Installed via an Unusual Client for Privilege Escalation
2 rules 1 TTPIdentifies the creation of a Windows service by an unusual client process, which can be leveraged to escalate privileges from administrator to SYSTEM by exploiting misconfigurations or vulnerabilities in the service creation process.
VeeamVssSupport +6
privilege-escalation
windows-service
windows
2r
1t
medium
advisory
WMI Incoming Lateral Movement
3 rules 2 TTPsDetection of processes executed via Windows Management Instrumentation (WMI) on a remote host indicating potential adversary lateral movement.
HPWBEM +3
lateral-movement
wmi
windows
3r
2t
medium
advisory
Remote Execution of Windows Services via RPC
2 rules 2 TTPsDetection of remote execution of Windows services over RPC by correlating `services.exe` network connections and spawned child processes, potentially indicating lateral movement.
SCCM
lateral-movement
execution
windows
2r
2t