Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

Persistence artefact removed via service, task or account deletion

Matches process creation where the command line removes one of the artefacts an operator would have had to leave behind to persist: `sc delete` for a service, `schtasks /delete` for a scheduled task, `reg delete` aimed at a Run key, an Image File Execution Options debugger value or a CurrentControlSet\Services key, `net user /delete` for a local account, and the PowerShell cmdlet forms when the cmdlet name is on the command line rather than inside a script file. The service, task, registry and account selections each pair the binary on `Image` with the verb on `CommandLine`, because the verbs alone are far too common to stand on their own; the cmdlet selection has no `Image` gate, since the cmdlet name is distinctive on its own. The registry arm additionally requires a persistence key path — Run/RunOnce and Image File Execution Options are the examples MITRE gives under its `TargetRegistryPathRegex` knob, and the `CurrentControlSet\Services` path is added here — so that `reg delete` of arbitrary configuration does not match. Because that arm is gated on `reg.exe`, the PowerShell registry-provider route (`Remove-ItemProperty -Path 'HKLM:\...\CurrentVersion\Run'`) is not covered. The rule is written in the Sysmon EventID 1 vocabulary the brief names — `Image` and `CommandLine`; a Security 4688 feed carries the same behaviour under `NewProcessName` and needs both Audit Process Creation and the separate Include command line in process creation events policy before `CommandLine` is populated at all, so 4688 cannot be substituted without a field mapping first. The brief's remaining legs are separate feeds with their own field names and are not combined here: 4726 account deletion, 4657 registry value modification, and TaskScheduler 106. Deletion performed through an API — a service control call, `Unregister-ScheduledTask` inside a script block, a registry delete from compiled code — never reaches a command line and is invisible to this rule. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0040, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: Persistence artefact removed via service, task or account deletionid: a7435f8e-1f74-4498-8f9e-8410019b13c0status: experimentaldescription: |  Matches process creation where the command line removes one of the artefacts an  operator would have had to leave behind to persist: `sc delete` for a service,  `schtasks /delete` for a scheduled task, `reg delete` aimed at a Run key, an  Image File Execution Options debugger value or a CurrentControlSet\Services  key, `net user /delete` for a local account, and the PowerShell cmdlet forms  when the cmdlet name is on the command line rather than inside a script file.  The service, task, registry and account selections each pair the binary on  `Image` with the verb on `CommandLine`, because the verbs alone are far too  common to stand on their own; the cmdlet selection has no `Image` gate, since  the cmdlet name is distinctive on its own. The registry arm additionally  requires a persistence key path — Run/RunOnce and Image File Execution Options  are the examples MITRE gives under its `TargetRegistryPathRegex` knob, and the  `CurrentControlSet\Services` path is added here — so that `reg delete` of  arbitrary configuration does not match. Because that arm is gated on  `reg.exe`, the PowerShell registry-provider route (`Remove-ItemProperty -Path  'HKLM:\...\CurrentVersion\Run'`) is not covered. The rule is  written in the Sysmon EventID 1 vocabulary the brief names — `Image` and  `CommandLine`; a Security 4688 feed carries the same behaviour under  `NewProcessName` and needs both Audit Process Creation and the separate  Include command line in process creation events policy before `CommandLine`  is populated at all, so 4688 cannot be substituted without a field mapping  first. The brief's remaining legs are separate feeds with their own field names  and are not combined here: 4726 account deletion, 4657 registry value  modification, and TaskScheduler 106. Deletion performed through an API — a  service control call, `Unregister-ScheduledTask` inside a script block, a  registry delete from compiled code — never reaches a command line and is  invisible to this rule.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0040, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1070/009  - https://attack.mitre.org/detectionstrategies/DET0040author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.defense-evasion  - attack.t1070.009logsource:  category: process_creation  product: windowsdetection:  selection_service:    Image|endswith: '\sc.exe'    CommandLine|contains: ' delete '  selection_task:    Image|endswith: '\schtasks.exe'    CommandLine|contains|windash: '/delete'  selection_reg_verb:    Image|endswith: '\reg.exe'    CommandLine|contains: ' delete '  selection_reg_key:    CommandLine|contains:      - '\CurrentVersion\Run'      - '\Image File Execution Options\'      - '\CurrentControlSet\Services\'  selection_account:    Image|endswith:      - '\net.exe'      - '\net1.exe'    CommandLine|contains|all:      - ' user '      - '/delete'  selection_cmdlet:    CommandLine|contains:      - 'Unregister-ScheduledTask'      - 'Remove-LocalUser'      - 'Remove-Service'  condition: selection_service or selection_task or (selection_reg_verb and selection_reg_key) or selection_account or selection_cmdletfalsepositives:  - "Application and driver uninstallers, which call `sc delete` to drop their own service and `schtasks /delete` to drop their updater task on every uninstall and on many major-version upgrades. On a fleet with normal software churn this is the single largest source of matches in the rule, and nothing on the command line separates it from an operator cleaning up."  - "Software deployment and configuration-management agents — Configuration Manager task sequences, Intune remediation scripts, Chocolatey and MSI custom actions — that remove stale services, tasks and Run values as SYSTEM during maintenance windows. MITRE's `DeletedScheduledTaskName` knob, populated with the recurring task names a given estate produces, is where these belong."  - "Helpdesk and re-imaging scripts running `net user <name> /delete` to remove a temporary, contractor or shared local account when a machine is re-issued. MITRE's `DeletedAccountGroupScope` knob is there to narrow this to privileged or recently created accounts."  - "Endpoint security, backup and printer vendor repair utilities that delete their own `CurrentControlSet\\Services` entry or an Image File Execution Options debugger value as part of a self-heal, uninstall-reinstall or driver rollback."level: low

Sentinel · KQL

Run this as a search.

DeviceProcessEvents| where (((((FolderPath endswith "\\sc.exe" and ProcessCommandLine contains " delete ") or (FolderPath endswith "\\schtasks.exe" and (ProcessCommandLine contains "-delete" or ProcessCommandLine contains "/delete" or ProcessCommandLine contains "–delete" or ProcessCommandLine contains "—delete" or ProcessCommandLine contains "―delete"))) or ((FolderPath endswith "\\reg.exe" and ProcessCommandLine contains " delete ") and (ProcessCommandLine contains "\\CurrentVersion\\Run" or ProcessCommandLine contains "\\Image File Execution Options\\" or ProcessCommandLine contains "\\CurrentControlSet\\Services\\"))) or ((FolderPath endswith "\\net.exe" or FolderPath endswith "\\net1.exe") and (ProcessCommandLine contains " user " and ProcessCommandLine contains "/delete"))) or (ProcessCommandLine contains "Unregister-ScheduledTask" or ProcessCommandLine contains "Remove-LocalUser" or ProcessCommandLine contains "Remove-Service"))

Splunk · SPL

Run this as a search.

index=* (((((Image="*\\sc.exe" AND CommandLine="* delete *") OR (Image="*\\schtasks.exe" AND (CommandLine="*-delete*" OR CommandLine="*/delete*" OR CommandLine="*–delete*" OR CommandLine="*—delete*" OR CommandLine="*―delete*"))) OR ((Image="*\\reg.exe" AND CommandLine="* delete *") AND (CommandLine="*\\CurrentVersion\\Run*" OR CommandLine="*\\Image File Execution Options\\*" OR CommandLine="*\\CurrentControlSet\\Services\\*"))) OR ((Image="*\\net.exe" OR Image="*\\net1.exe") AND (CommandLine="* user *" AND CommandLine="*/delete*"))) OR (CommandLine="*Unregister-ScheduledTask*" OR CommandLine="*Remove-LocalUser*" OR CommandLine="*Remove-Service*"))

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE (((((TO_LOWER(process.executable) LIKE "*\\\\sc.exe" AND TO_LOWER(process.command_line) LIKE "* delete *") OR (TO_LOWER(process.executable) LIKE "*\\\\schtasks.exe" AND (TO_LOWER(process.command_line) LIKE "*-delete*" OR TO_LOWER(process.command_line) LIKE "*/delete*" OR TO_LOWER(process.command_line) LIKE "*–delete*" OR TO_LOWER(process.command_line) LIKE "*—delete*" OR TO_LOWER(process.command_line) LIKE "*―delete*"))) OR ((TO_LOWER(process.executable) LIKE "*\\\\reg.exe" AND TO_LOWER(process.command_line) LIKE "* delete *") AND (TO_LOWER(process.command_line) LIKE "*\\\\currentversion\\\\run*" OR TO_LOWER(process.command_line) LIKE "*\\\\image file execution options\\\\*" OR TO_LOWER(process.command_line) LIKE "*\\\\currentcontrolset\\\\services\\\\*"))) OR ((TO_LOWER(process.executable) LIKE "*\\\\net.exe" OR TO_LOWER(process.executable) LIKE "*\\\\net1.exe") AND (TO_LOWER(process.command_line) LIKE "* user *" AND TO_LOWER(process.command_line) LIKE "*/delete*"))) OR (TO_LOWER(process.command_line) LIKE "*unregister-scheduledtask*" OR TO_LOWER(process.command_line) LIKE "*remove-localuser*" OR TO_LOWER(process.command_line) LIKE "*remove-service*"))

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,process_creation,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <!-- 5 rules: the Sigma condition ORs across different fields,       which one rule cannot express. Any one matching is a hit. -->  <rule id="100000" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="Image" type="pcre2">(?i)\\sc\.exe$</field>    <field name="CommandLine" type="pcre2">(?i) delete </field>    <description>Persistence artefact removed via service, task or account deletion (1/5)</description>    <mitre>      <id>T1070.009</id>    </mitre>  </rule>   <rule id="100001" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="Image" type="pcre2">(?i)\\schtasks\.exe$</field>    <field name="CommandLine" type="pcre2">(?i)(-delete|/delete|–delete|—delete|―delete)</field>    <description>Persistence artefact removed via service, task or account deletion (2/5)</description>    <mitre>      <id>T1070.009</id>    </mitre>  </rule>   <rule id="100002" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="Image" type="pcre2">(?i)\\reg\.exe$</field>    <field name="CommandLine" type="pcre2">(?i) delete </field>    <field name="CommandLine" type="pcre2">(?i)(\\CurrentVersion\\Run|\\Image File Execution Options\\|\\CurrentControlSet\\Services\\)</field>    <description>Persistence artefact removed via service, task or account deletion (3/5)</description>    <mitre>      <id>T1070.009</id>    </mitre>  </rule>   <rule id="100003" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="Image" type="pcre2">(?i)(\\net\.exe$|\\net1\.exe$)</field>    <field name="CommandLine" type="pcre2">(?i)(?=.*(?: user ))(?=.*(?:/delete)).*</field>    <description>Persistence artefact removed via service, task or account deletion (4/5)</description>    <mitre>      <id>T1070.009</id>    </mitre>  </rule>   <rule id="100004" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="CommandLine" type="pcre2">(?i)(Unregister-ScheduledTask|Remove-LocalUser|Remove-Service)</field>    <description>Persistence artefact removed via service, task or account deletion (5/5)</description>    <mitre>      <id>T1070.009</id>    </mitre>  </rule></group>

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.