What the agents hand your team.
This is a product preview: sample outputs in the format the agents produce, not customer data. They follow one public technique, T1543.003 (Create or Modify System Process: Windows Service), and use generic names such as index=wineventlog, hosts WKS-0xx and the domain example.local.
Each panel is an excerpt. Real outputs carry the full query and event links behind every line.
Threat brief: Windows Service creation and modification
Adversaries create or change Windows services to run their code at boot or with SYSTEM rights. Six procedures found, every one tied to a public source.
| ID | Procedure | ATT&CK | Source |
|---|---|---|---|
| P1 | New service created from the command line with a service control tool | T1543.003 | Atomic Red Team T1543.003-2 |
| P2 | New service created through PowerShell | T1543.003 | Atomic Red Team T1543.003-3 |
| P3 | Existing service reconfigured to run a different binary | T1543.003 | Atomic Red Team T1543.003-1 |
| P4 | Service configuration written directly to the registry | T1543.003, T1112 | Atomic Red Team T1543.003-4; MITRE ATT&CK |
| P5 | Service created on a remote host to run a payload | T1543.003, T1569.002 | MITRE ATT&CK T1569.002 |
| P6 | Service binary placed in a user-writable folder | T1543.003 | MITRE ATT&CK T1543.003 |
Sources cited (excerpt, 4 of 9)
- MITRE ATT&CK, T1543.003 Create or Modify System Process: Windows Service
- MITRE ATT&CK, T1569.002 System Services: Service Execution
- Atomic Red Team, tests T1543.003-1 to T1543.003-4
- Microsoft documentation for service installation events
Open questions for the engineer
Does the environment log process command lines? P6 depends on it.
Coverage report: is the data there for each procedure?
Each source was checked with live searches in the lab. An empty result was re-checked with a smaller window and a known-positive control before it was marked missing.
| Procedure | Data source | Status | Gate |
|---|---|---|---|
| P1 | Service install events, Endpoint.Services datamodel | available normalized | GREEN |
| P2 | Service install events, Endpoint.Services datamodel | available normalized | GREEN |
| P3 | Registry events, Endpoint.Registry datamodel | available normalized | GREEN |
| P4 | Registry events, Endpoint.Registry datamodel | available normalized | GREEN |
| P5 | Remote logon and service events in index=wineventlog, not mapped to a datamodel | available raw | YELLOW |
| P6 | Process creation with command line | missing | RED |
- Summary
- 4 detectable, 1 raw only, 1 missing log
- Remediation
- P5: map remote logon fields to the Authentication datamodel. P6: enable command-line process auditing on WKS-0xx hosts.
- Effect
- P6 variants are skipped in simulation and reported as a telemetry gap, not as a detection failure.
Validation report: does it fire, and how noisy is it?
Six Atomic Red Team variants ran in the synthetic lab, each with a signed marker so only genuine test events count. The false-positive baseline covered 14 days of lab background activity.
| Variant | Procedure | Result |
|---|---|---|
| T1543.003-1 | P3 | fired |
| T1543.003-2 | P1 | fired |
| T1543.003-3 | P2 | fired |
| T1543.003-4 | P4 | fired |
| remote variant | P5 | fired |
| user-path variant | P6 | telemetry gap |
- True positives
- 5 of 6 variants fired, 0 missed, 1 telemetry gap
- False positives
- 0.4 per day over 14 days, against a team target of 1.0 per day
- FP source
- Service reinstalls by
svc_backupon WKS-014 and WKS-027
Routing
- Telemetry gap on P6 goes back to Coverage as an onboarding request, not to Build.
- The
svc_backupexception is proposed in the filter macro, with a justification, for the engineer at the approval gate.
Tuning diff: which alerts would disappear, and why
A generic live rule produced 477 alerts in 30 days of synthetic lab history. The agent grouped them into clusters, labelled each one, and proposed the smallest change that removes only the benign clusters.
| Cluster | Label | Alerts | Proposal |
|---|---|---|---|
| C1 | Backup agent reinstalls its service (svc_backup, WKS-0xx) | 312 | drop |
| C2 | Software deployment tool updates its agent service | 140 | drop |
| C3 | Manual service installs by IT admins on servers | 22 | keep |
| C4 | Service binary in a user temp folder, unknown signer | 3 | keep |
- Tier chosen
- FILTER: two scoped exceptions in the filter macro. No threshold change, no rewrite of the search.
- Would disappear
- 452 alerts, all from C1 and C2. 0 from C3 or C4.
- Projected reduction
- 94.8% (477 to 25 alerts in the same 30 days)
Must-keep checks
- All 5 previously firing Atomic Red Team variants still fire after the change.
- Every C4 alert is still raised.
- Remaining volume is above zero, so the rule has not been silenced.
Rollback plan
Revert the merge request to restore the previous filter macro. A post-check after 7 days live compares alert volume and confirms C3 and C4 alerts still arrive; any drop there reopens the proposal.