A security analyst is investigating a sophisticated attack involving a custom malware variant that establishes persistent access through a scheduled task. The malware creates a new service that runs a PowerShell script from a specific, unusual folder path. The analyst needs to create a custom detection rule in Microsoft Defender XDR to identify future instances of this activity. Which KQL query snippet would MOST effectively identify the creation of a new service that executes a PowerShell script from a specific folder path?
- ADeviceRegistryEvents | where RegistryKey contains "\Services\" and RegistryValueData contains "powershell.exe"
- BDeviceProcessEvents | where FileName == "powershell.exe" and ProcessCommandLine contains "-ExecutionPolicy Bypass"
- CDeviceFileEvents | where FolderPath == "C:\ProgramData\Malware" and ActionType == "FileCreated"
- DDeviceProcessEvents | where InitiatingProcessFileName == "services.exe" and ProcessCommandLine contains "powershell.exe" and FolderPath contains "C:\ProgramData\Malware"
Show answer & explanationAnswer & explanation
Correct answer: D. DeviceProcessEvents | where InitiatingProcessFileName == "services.exe" and ProcessCommandLine contains "powershell.exe" and FolderPath contains "C:\ProgramData\Malware"
The scenario describes a *service* creating an *executable* (PowerShell) from a *specific folder path*. DeviceProcessEvents captures process creation. InitiatingProcessFileName == "services.exe" identifies services creating processes. ProcessCommandLine contains "powershell.exe" identifies the executable. FolderPath contains "C:\ProgramData\Malware" identifies the specific location. This query combines all necessary elements to detect the described activity.
Why the other options are wrong
- A. DeviceRegistryEvents can show service *configuration*, but not necessarily the *execution* of the PowerShell script by the service at runtime, nor the specific folder path from which the script is launched as a process.
- B. This only looks for PowerShell execution generally, not specifically initiated by a service or from a specific unusual path.
- C. DeviceFileEvents shows file creation, but not the *execution* of a service or a PowerShell script from that path.
KQL: Service-initiated PowerShell from FolderPath
A KQL query pattern in Microsoft Defender XDR's Advanced Hunting to detect malicious services initiating PowerShell scripts from specific, potentially suspicious, folder paths.
- Uses `DeviceProcessEvents` table.
- Filters by `InitiatingProcessFileName` (e.g., `services.exe`).
- Checks `ProcessCommandLine` for script execution.
- Identifies `FolderPath` for suspicious locations.
Memory trick: To catch a service running a script from a weird place, check the 'process events' for 'services.exe', 'powershell', and the 'folder path'.