Detecting Lateral Movement via Service Configuration Manager
Using Endpoint & Network telemetry to hunt for remote service usage for lateral movement
Descritption
result = ChangeServiceConfig(serviceInfo.serviceHandle, SERVICE_NO_CHANGE, SERVICE_DEMAND_START, 0, options.payload, null, IntPtr.Zero, null, null, null, null);The attack

Endpoint Telemetry



Network Telemetry

EQL Detections
Endpoint:

Network:

References
PreviousTA0008 : Lateral MovementNextDetecting CONTI CobaltStrike Lateral Movement Techniques - Part 1
Last updated