2017-03-07 09:24:06 +01:00
title : StoneDrill Service Install
2019-11-12 23:12:27 +01:00
id : 9e987c6c-4c1e-40d8-bd85-dd26fba8fdd6
description : This method detects a service install of the malicious Microsoft Network Realtime Inspection Service service described in StoneDrill report by Kaspersky
2017-03-07 09:24:06 +01:00
author : Florian Roth
2018-01-28 02:24:16 +03:00
references :
- https://securelist.com/blog/research/77725/from-shamoon-to-stonedrill/
2018-07-25 09:50:01 +02:00
tags :
- attack.persistence
- attack.g0064
- attack.t1050
2017-03-07 09:24:06 +01:00
logsource :
product : windows
service : system
detection :
selection :
EventID : 7045
2017-03-31 19:25:10 +02:00
ServiceName : NtsSrv
ServiceFileName : '* LocalService'
condition : selection
2017-03-07 09:24:06 +01:00
falsepositives :
- Unlikely
level : high