StoneDrill Service Install

This method detects a service install of the malicious Microsoft Network Realtime Inspection Service service described in StoneDrill report by Kaspersky

Sigma rule (View on GitHub)

 1title: StoneDrill Service Install
 2id: 9e987c6c-4c1e-40d8-bd85-dd26fba8fdd6
 3status: test
 4description: This method detects a service install of the malicious Microsoft Network Realtime Inspection Service service described in StoneDrill report by Kaspersky
 5references:
 6    - https://securelist.com/blog/research/77725/from-shamoon-to-stonedrill/
 7author: Florian Roth (Nextron Systems)
 8date: 2017-03-07
 9modified: 2021-11-30
10tags:
11    - attack.privilege-escalation
12    - attack.persistence
13    - attack.g0064
14    - attack.t1543.003
15    - detection.emerging-threats
16logsource:
17    product: windows
18    service: system
19detection:
20    selection:
21        Provider_Name: 'Service Control Manager'
22        EventID: 7045
23        ServiceName: NtsSrv
24        ImagePath|endswith: ' LocalService'
25    condition: selection
26falsepositives:
27    - Unlikely
28level: high

References

Related rules

to-top