Real-world descriptions of how a group, tool or campaign used a technique.
51 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1569.002 Service Execution |
MalwareProxysvc | Proxysvc registers itself as a service on the victim’s machine to run as a standalone process. |
| T1569.002 Service Execution |
MalwareStrongPity | StrongPity can install a service to execute itself as a service. |
| T1569.002 Service Execution |
MalwareTinyTurla | TinyTurla can install itself as a service on compromised machines. |
| T1569.002 Service Execution |
MalwareBad Rabbit | Bad Rabbit drops a file named |
| T1569.002 Service Execution |
MalwareOlympic Destroyer | Olympic Destroyer utilizes PsExec to help propagate itself across a network. |
| T1569.002 Service Execution |
MalwareMafalda | Mafalda can create a remote service, let it run once, and then delete it. |
| T1569.002 Service Execution |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware executes as a service when deployed. |
| T1569.002 Service Execution |
MalwareHOPLIGHT | HOPLIGHT has used svchost.exe to execute a malicious DLL . |
| T1569.002 Service Execution |
MalwareWastedLocker | WastedLocker can execute itself as a service. |
| T1569.002 Service Execution |
MalwareInvisiMole | InvisiMole has used Windows services as a way to execute its malicious payload. |
| T1569.002 Service Execution |
MalwareWhisperGate | WhisperGate can download and execute AdvancedRun.exe via `sc.exe`. |
| T1569.002 Service Execution |
MalwareOkrum | Okrum's loader can create a new service named NtmsSvc to execute the payload. |
| T1569.002 Service Execution |
MalwareRemoteCMD | RemoteCMD can execute commands remotely by creating a new service on the remote system. |
| T1569.002 Service Execution |
MalwareRagnar Locker | Ragnar Locker has used sc.exe to execute a service that it creates. |
| T1569.002 Service Execution |
MalwareNotPetya | NotPetya can use PsExec to help propagate itself across a network. |
| T1569.002 Service Execution |
MalwareHyperBro | HyperBro has the ability to start and stop a specified service. |
| T1569.002 Service Execution |
MalwareAnchor | Anchor can create and execute services to load its payload. |
| T1569.002 Service Execution |
MalwareBBSRAT | BBSRAT can start, stop, or delete services. |
| T1569.002 Service Execution |
MalwareClambling | Clambling can create and start services on a compromised host. |
| T1569.002 Service Execution |
MalwareDarkGate | DarkGate tries to elevate privileges to |
| T1569.002 Service Execution |
MalwareLockBit 3.0 | LockBit 3.0 can use PsExec to execute commands and payloads. |
| T1569.002 Service Execution |
MalwareHydraq | Hydraq uses svchost.exe to execute a malicious DLL included in a new service group. |
| T1569.002 Service Execution |
MalwareNetwalker | Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload. |
| T1569.002 Service Execution |
MalwareEmbargo | Embargo has created a service named irnagentd that executed the MDeployer loader after the system is rebooted in Safe Mode. |
| T1569.002 Service Execution |
Malwaregh0st RAT | gh0st RAT can execute its service if the Service key exists. If the key does not exist, gh0st RAT will create and run the service. |
| T1569.002 Service Execution |
MalwareShamoon | Shamoon creates a new service named “ntssrv” to execute the payload. Shamoon can also spread via PsExec. |
| T1569.002 Service Execution |
MalwareAttor | Attor's dispatcher can be executed as a service. |
| T1569.002 Service Execution |
MalwareHermeticWiper | HermeticWiper can create system services to aid in executing the payload. |
| T1569.002 Service Execution |
MalwarePysa | |
| T1569.002 Service Execution |
MalwarePandora | Pandora has the ability to install itself as a Windows service. |
| T1569.002 Service Execution |
MalwareCobalt Strike | Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services. |
| T1569.002 Service Execution |
MalwareWingbird | Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file. |
| T1569.002 Service Execution |
MalwareIPsec Helper | IPsec Helper is run as a Windows service in victim environments. |
| T1569.002 Service Execution |
MalwareSysUpdate | SysUpdate can manage services and processes. |
| T1569.002 Service Execution |
MalwareZxShell | ZxShell can create a new service for execution. |
| T1569.002 Service Execution |
MalwareWinnti for Windows | Winnti for Windows can run as a service using svchost.exe. |
| T1569.002 Service Execution |
MalwareDEADWOOD | DEADWOOD can be executed as a service using various names, such as |
| T1569.002 Service Execution |
MalwareLoudMiner | LoudMiner started the cryptomining virtual machine as a service on the infected machine. |
| T1569.002 Service Execution |
MalwareNet Crawler | Net Crawler uses PsExec to perform remote service manipulation to execute a copy of itself as part of lateral movement. |
| T1569.002 Service Execution |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has the capability to start services. |
| T1569.002 Service Execution |
MalwareHermeticWizard | HermeticWizard can use `OpenRemoteServiceManager` to create a service. |
| T1569.002 Service Execution |
ToolNet | The |
| T1569.002 Service Execution |
ToolImpacket | Impacket contains various modules emulating other service execution tools such as PsExec. |
| T1569.002 Service Execution |
ToolEmpire | Empire can use PsExec to execute a payload on a remote host. |
| T1569.002 Service Execution |
ToolPoshC2 | PoshC2 contains an implementation of PsExec for remote execution. |
| T1569.002 Service Execution |
ToolxCmd | xCmd can be used to execute binaries on remote systems by creating and starting a service. |
| T1569.002 Service Execution |
ToolBrute Ratel C4 | Brute Ratel C4 can create Windows system services for execution. |
| T1569.002 Service Execution |
ToolWinexe | Winexe installs a service on the remote system, executes the command, then uninstalls the service. |
| T1569.002 Service Execution |
ToolKoadic | |
| T1569.002 Service Execution |
ToolPupy | Pupy uses PsExec to execute a payload or commands on a remote host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.