Skip to content

Siemphony is in beta and still being built. How a rule earns its badge.

Siemphony’s repertoire

Service execution or recovery registry value rewritten

AN1195's `MonitoredServiceKeys` knob names `ImagePath`, `ServiceDll`, `FailureCommand` and the `Parameters` subkey as the values a weak ACL lets an attacker rewrite to redirect what a service launches; this rule matches a registry write under `CurrentControlSet\Services\` to any of those value names. The brief's `sigmaLogsource` for this leg is `registry_set` with no `service` qualifier, which is Sysmon's EventID 13 shape (`TargetObject` carries the full key-plus-value path, `Details` carries the written data), and that is the vocabulary this rule is written in. The brief also lists Security EventID 4657 for the same analytic, but 4657 is a structurally different feed — it splits the key and value into separate `ObjectName` and `ObjectValueName` fields rather than Sysmon's single `TargetObject` — so turning on *Audit Registry* and a SACL on the Services key would not make this rule see anything; it would need its own field mapping. The System 7040 leg (service start-type changed) is a different signal again — a configuration change surfaced by the Service Control Manager, not the registry write itself — and is likewise not combined here. This rule cannot express AN1195's `BaselineServiceConfig` or `TimeWindow` knobs: comparing a new value against a known-good baseline, or correlating the write with the service process that starts afterward, both need state or a cross-event join lib/sigma does not model, so a hit is evidence of a rewrite and not by itself evidence that the new value is wrong. Sysmon is not installed by default, and most shipped configurations exclude the high-volume `Services` subtree from EventID 13 entirely — on such a host this rule returns zero rows, which reads as quiet but means blind. UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0427, not hand-written and not tested by its author. Any lab result is on this rule's own page.Full description

The detection

The 4 SIEM queries below are previews produced by Siemphony’s own translator, not pySigma, and none has been executed against a real backend — review before you deploy.

detection.yml

title: Service execution or recovery registry value rewrittenid: 77e94954-f423-4b75-a9b7-5047c8325302status: experimentaldescription: |  AN1195's `MonitoredServiceKeys` knob names `ImagePath`, `ServiceDll`,  `FailureCommand` and the `Parameters` subkey as the values a weak ACL lets  an attacker rewrite to redirect what a service launches; this rule matches  a registry write under `CurrentControlSet\Services\` to any of those value  names. The brief's `sigmaLogsource` for this leg is `registry_set` with no  `service` qualifier, which is Sysmon's EventID 13 shape (`TargetObject`  carries the full key-plus-value path, `Details` carries the written data),  and that is the vocabulary this rule is written in. The brief also lists  Security EventID 4657 for the same analytic, but 4657 is a structurally  different feed — it splits the key and value into separate `ObjectName` and  `ObjectValueName` fields rather than Sysmon's single `TargetObject` — so  turning on *Audit Registry* and a SACL on the Services key would not make  this rule see anything; it would need its own field mapping. The System  7040 leg (service start-type changed) is a different signal again — a  configuration change surfaced by the Service Control Manager, not the  registry write itself — and is likewise not combined here. This rule cannot  express AN1195's `BaselineServiceConfig` or `TimeWindow` knobs: comparing a  new value against a known-good baseline, or correlating the write with the  service process that starts afterward, both need state or a cross-event  join lib/sigma does not model, so a hit is evidence of a rewrite and not by  itself evidence that the new value is wrong. Sysmon is not installed by  default, and most shipped configurations exclude the high-volume `Services`  subtree from EventID 13 entirely — on such a host this rule returns zero  rows, which reads as quiet but means blind.  UNVERIFIED AS AUTHORED — derived from MITRE ATT&CK DET0427, not hand-written and not tested by its author. Any lab result is on this rule's own page.references:  - https://attack.mitre.org/techniques/T1574/011  - https://attack.mitre.org/detectionstrategies/DET0427author: Siemphony pipeline (machine-derived from MITRE ATT&CK v19.2)date: 2026-08-16tags:  - attack.defense-evasion  - attack.execution  - attack.t1574.011logsource:  category: registry_set  product: windowsdetection:  selection_service_key:    TargetObject|contains: '\CurrentControlSet\Services\'  selection_value_name:    TargetObject|endswith:      - '\ImagePath'      - '\FailureCommand'      - '\Parameters\ServiceDll'  condition: selection_service_key and selection_value_namefalsepositives:  - "Ordinary service installation through sc.exe create, New-Service, or an MSI/EXE installer's service-install custom action, which writes ImagePath for every new service on every host — this is the highest-volume source of matches here and fires on essentially any software or driver install that registers a service."  - "Windows Update and component servicing rewriting ServiceDll for in-box svchost-hosted services (BITS, wuauserv, and similar) as part of a cumulative update, even though the referenced DLL file itself did not move."  - "Endpoint-management agents such as Configuration Manager or Intune reconfiguring FailureCommand or restart-recovery actions across a fleet as part of a routine service-hardening baseline."  - "Plug and Play driver installation via pnputil or Device Manager, which creates or updates the ImagePath value for a newly installed kernel or filter driver service."level: low

Sentinel · KQL

Run this as a search.

DeviceRegistryEvents| where (RegistryKey contains "\\CurrentControlSet\\Services\\" and (RegistryKey endswith "\\ImagePath" or RegistryKey endswith "\\FailureCommand" or RegistryKey endswith "\\Parameters\\ServiceDll"))

Splunk · SPL

Run this as a search.

index=* (TargetObject="*\\CurrentControlSet\\Services\\*" AND (TargetObject="*\\ImagePath" OR TargetObject="*\\FailureCommand" OR TargetObject="*\\Parameters\\ServiceDll"))

Elastic · ES|QL

Run this as a search.

FROM logs-*| WHERE (TO_LOWER(registry.path) LIKE "*\\\\currentcontrolset\\\\services\\\\*" AND (TO_LOWER(registry.path) LIKE "*\\\\imagepath" OR TO_LOWER(registry.path) LIKE "*\\\\failurecommand" OR TO_LOWER(registry.path) LIKE "*\\\\parameters\\\\servicedll"))

Wazuh · XML rule

Deploy to your manager — this is a rule, not a search.

<group name="sigma,windows,registry_set,">  <!-- Rule ids must be unique on your manager; 100000+ is the user range. -->  <rule id="100000" level="5">    <!-- Set <if_sid> to the decoder/base rule for windows so this only evaluates relevant events. -->    <field name="TargetObject" type="pcre2">(?i)\\CurrentControlSet\\Services\\</field>    <field name="TargetObject" type="pcre2">(?i)(\\ImagePath$|\\FailureCommand$|\\Parameters\\ServiceDll$)</field>    <description>Service execution or recovery registry value rewritten</description>    <mitre>      <id>T1574.011</id>    </mitre>  </rule></group>

Verdicts · reactions · comments

Community

Verdicts from engineers who actually deployed it, and the conversation around it.

Log in to react
Not yet reported on

Nobody has run this in a real environment and said what happened.

Verdicts from engineers who deployed it

0 cast

No verdicts reported yet. The first one is worth more than the tenth — say what you ran it against.

Log in to report a verdict.

Log in to join the discussion.

No comments yet. Someone who deploys this will have something to say about it.