Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard

A security analyst is investigating a sophisticated attack involving a custom malware variant that establishes persistent access through a scheduled task. The malware creates a new service that runs a PowerShell script from a specific, unusual folder path. The analyst needs to create a custom detection rule in Microsoft Defender XDR to identify future instances of this activity. Which KQL query snippet would MOST effectively identify the creation of a new service that executes a PowerShell script from a specific folder path?

  1. ADeviceRegistryEvents | where RegistryKey contains "\Services\" and RegistryValueData contains "powershell.exe"
  2. BDeviceProcessEvents | where FileName == "powershell.exe" and ProcessCommandLine contains "-ExecutionPolicy Bypass"
  3. CDeviceFileEvents | where FolderPath == "C:\ProgramData\Malware" and ActionType == "FileCreated"
  4. DDeviceProcessEvents | where InitiatingProcessFileName == "services.exe" and ProcessCommandLine contains "powershell.exe" and FolderPath contains "C:\ProgramData\Malware"
Show answer & explanation

Correct answer: D. DeviceProcessEvents | where InitiatingProcessFileName == "services.exe" and ProcessCommandLine contains "powershell.exe" and FolderPath contains "C:\ProgramData\Malware"

The scenario describes a *service* creating an *executable* (PowerShell) from a *specific folder path*. DeviceProcessEvents captures process creation. InitiatingProcessFileName == "services.exe" identifies services creating processes. ProcessCommandLine contains "powershell.exe" identifies the executable. FolderPath contains "C:\ProgramData\Malware" identifies the specific location. This query combines all necessary elements to detect the described activity.

Why the other options are wrong

  • A. DeviceRegistryEvents can show service *configuration*, but not necessarily the *execution* of the PowerShell script by the service at runtime, nor the specific folder path from which the script is launched as a process.
  • B. This only looks for PowerShell execution generally, not specifically initiated by a service or from a specific unusual path.
  • C. DeviceFileEvents shows file creation, but not the *execution* of a service or a PowerShell script from that path.

KQL: Service-initiated PowerShell from FolderPath

A KQL query pattern in Microsoft Defender XDR's Advanced Hunting to detect malicious services initiating PowerShell scripts from specific, potentially suspicious, folder paths.

  • Uses `DeviceProcessEvents` table.
  • Filters by `InitiatingProcessFileName` (e.g., `services.exe`).
  • Checks `ProcessCommandLine` for script execution.
  • Identifies `FolderPath` for suspicious locations.

Memory trick: To catch a service running a script from a weird place, check the 'process events' for 'services.exe', 'powershell', and the 'folder path'.

More Mitigate threats using Microsoft Defender XDR questions