Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1569.002 Service Execution |
MalwareRemoteCMD | RemoteCMD can execute commands remotely by creating a new service on the remote system. |
| T1569.002 Service Execution |
MalwareRagnar Locker | Ragnar Locker has used sc.exe to execute a service that it creates. |
| T1569.002 Service Execution |
MalwareNotPetya | NotPetya can use PsExec to help propagate itself across a network. |
| T1569.002 Service Execution |
MalwareHyperBro | HyperBro has the ability to start and stop a specified service. |
| T1569.002 Service Execution |
MalwareAnchor | Anchor can create and execute services to load its payload. |
| T1569.002 Service Execution |
MalwareBBSRAT | BBSRAT can start, stop, or delete services. |
| T1569.002 Service Execution |
MalwareClambling | Clambling can create and start services on a compromised host. |
| T1569.002 Service Execution |
MalwareDarkGate | DarkGate tries to elevate privileges to |
| T1569.002 Service Execution |
MalwareLockBit 3.0 | LockBit 3.0 can use PsExec to execute commands and payloads. |
| T1569.002 Service Execution |
MalwareHydraq | Hydraq uses svchost.exe to execute a malicious DLL included in a new service group. |
| T1569.002 Service Execution |
MalwareNetwalker | Operators deploying Netwalker have used psexec and certutil to retrieve the Netwalker payload. |
| T1569.002 Service Execution |
MalwareEmbargo | Embargo has created a service named irnagentd that executed the MDeployer loader after the system is rebooted in Safe Mode. |
| T1569.002 Service Execution |
Malwaregh0st RAT | gh0st RAT can execute its service if the Service key exists. If the key does not exist, gh0st RAT will create and run the service. |
| T1569.002 Service Execution |
MalwareShamoon | Shamoon creates a new service named “ntssrv” to execute the payload. Shamoon can also spread via PsExec. |
| T1569.002 Service Execution |
MalwareAttor | Attor's dispatcher can be executed as a service. |
| T1569.002 Service Execution |
MalwareHermeticWiper | HermeticWiper can create system services to aid in executing the payload. |
| T1569.002 Service Execution |
MalwarePysa | |
| T1569.002 Service Execution |
MalwarePandora | Pandora has the ability to install itself as a Windows service. |
| T1569.002 Service Execution |
MalwareCobalt Strike | Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services. |
| T1569.002 Service Execution |
MalwareWingbird | Wingbird uses services.exe to register a new autostart service named "Audit Service" using a copy of the local lsass.exe file. |
| T1569.002 Service Execution |
MalwareIPsec Helper | IPsec Helper is run as a Windows service in victim environments. |
| T1569.002 Service Execution |
MalwareSysUpdate | SysUpdate can manage services and processes. |
| T1569.002 Service Execution |
MalwareZxShell | ZxShell can create a new service for execution. |
| T1569.002 Service Execution |
MalwareWinnti for Windows | Winnti for Windows can run as a service using svchost.exe. |
| T1569.002 Service Execution |
MalwareDEADWOOD | DEADWOOD can be executed as a service using various names, such as |
| T1569.002 Service Execution |
MalwareLoudMiner | LoudMiner started the cryptomining virtual machine as a service on the infected machine. |
| T1569.002 Service Execution |
MalwareNet Crawler | Net Crawler uses PsExec to perform remote service manipulation to execute a copy of itself as part of lateral movement. |
| T1569.002 Service Execution |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has the capability to start services. |
| T1569.002 Service Execution |
MalwareHermeticWizard | HermeticWizard can use `OpenRemoteServiceManager` to create a service. |
| T1569.002 Service Execution |
ToolNet | The |
| T1569.002 Service Execution |
ToolImpacket | Impacket contains various modules emulating other service execution tools such as PsExec. |
| T1569.002 Service Execution |
ToolEmpire | Empire can use PsExec to execute a payload on a remote host. |
| T1569.002 Service Execution |
ToolPoshC2 | PoshC2 contains an implementation of PsExec for remote execution. |
| T1569.002 Service Execution |
ToolxCmd | xCmd can be used to execute binaries on remote systems by creating and starting a service. |
| T1569.002 Service Execution |
ToolBrute Ratel C4 | Brute Ratel C4 can create Windows system services for execution. |
| T1569.002 Service Execution |
ToolWinexe | Winexe installs a service on the remote system, executes the command, then uninstalls the service. |
| T1569.002 Service Execution |
ToolKoadic | |
| T1569.002 Service Execution |
ToolPupy | Pupy uses PsExec to execute a payload or commands on a remote host. |
| T1569.002 Service Execution |
ToolPsExec | Microsoft Sysinternals PsExec is a popular administration tool that can be used to execute binaries on remote systems using a temporary Windows service. |
| T1569.003 Systemctl |
GroupTeamTNT | TeamTNT has created system services to execute cryptocurrency mining software. |
| T1569.003 Systemctl |
MalwareCanisterWorm | CanisterWorm has used executed `systemctl --user daemon-reload` to reload systemd, then enables and starts the malicious service. |
| T1570 Lateral Tool Transfer |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors used Impacket to remotely stage and execute payloads via WMI. |
| T1570 Lateral Tool Transfer |
Campaign2015 Ukraine Electric Power Attack | During the 2015 Ukraine Electric Power Attack, Sandworm Team moved their tools laterally within the corporate network and between the ICS and corporate network. |
| T1570 Lateral Tool Transfer |
CampaignC0018 | During C0018, the threat actors transferred the SoftPerfect Network Scanner and other tools to machines in the network using AnyDesk and PDQ Deploy. |
| T1570 Lateral Tool Transfer |
CampaignC0015 | During C0015, the threat actors used WMI to load Cobalt Strike onto additional hosts within a compromised network. |
| T1570 Lateral Tool Transfer |
CampaignHomeLand Justice | During HomeLand Justice, threat actors initiated a process named Mellona.exe to spread the ROADSWEEP file encryptor and a persistence script to a list of internal machines. |
| T1570 Lateral Tool Transfer |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries had placed the malicious payload on an accessible network share to facilitate propagation. |
| T1570 Lateral Tool Transfer |
Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used `move` to transfer files to a network share. |
| T1570 Lateral Tool Transfer |
CampaignOperation Wocao | During Operation Wocao, threat actors used SMB to copy files to and from target systems. |
| T1570 Lateral Tool Transfer |
Campaign2022 Ukraine Electric Power Attack | During the 2022 Ukraine Electric Power Attack, Sandworm Team used a Group Policy Object (GPO) to copy CaddyWiper's executable `msserver.exe` from a staging server to a local hard drive before deployment. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.