Sub-technique of T1543 Create or Modify System Process.View on attack.mitre.org
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.
Adversaries may install a new service or modify an existing service to execute at startup in order to persist on a system. Service configurations can be set or modified using system utilities (such as sc.exe), by directly modifying the Registry, or by interacting directly with the Windows API.
Adversaries may also use services to install and execute malicious drivers. For example, after dropping a driver file (ex: `.sys`) to disk, the payload can be loaded and registered via Native API functions such as `CreateServiceW()` (or manually via functions such as `ZwLoadDriver()` and `ZwSetValueKey()`), by creating the required service Registry values (i.e. Modify Registry), or by using command-line utilities such as `PnPUtil.exe`. Adversaries may leverage these drivers as Rootkits to hide the presence of malicious activity on a system. Adversaries may also load a signed yet vulnerable driver onto a compromised machine (known as "Bring Your Own Vulnerable Driver" (BYOVD)) as part of Exploitation for Privilege Escalation.
Services may be created with administrator privileges but are executed under SYSTEM privileges, so an adversary may also use a service to escalate privileges. Adversaries may also directly start services through Service Execution.
To make detection analysis more challenging, malicious services may also incorporate Masquerade Task or Service (ex: using a service and/or payload name related to a legitimate OS or benign software component). Adversaries may also create ‘hidden’ services (i.e., Hide Artifacts), for example by using the `sc sdset` command to set service permissions via the Service Descriptor Definition Language (SDDL). This may hide a Windows service from the view of standard service enumeration methods such as `Get-Service`, `sc query`, and `services.exe`.
Rules on DetectionCode tagged with T1543.003.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| CMD Echo Pipe - Escalation | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Impacket Lateral Movement Commandline Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Impacket Lateral Movement smbexec CommandLine Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Impacket Lateral Movement WMIExec Commandline Parameters | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Possible Lateral Movement PowerShell Spawn | Anomaly | NULL | Sysmon EventID 1, CrowdStrike ProcessRollup2 |
| Randomly Generated Windows Service Name | Hunting | NULL | Windows Event Log System 7045 |
| Sc exe Manipulating Windows Services | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Services LOLBAS Execution Process Spawn | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Suspicious Driver Loaded Path | TTP | NULL | Sysmon EventID 6 |
| Windows Admin Password Changed by Non-Admin | TTP | NULL | Windows Event Log Security 4723 |
| Windows Bluetooth Service Installed From Uncommon Location | Anomaly | NULL | Windows Event Log System 7045 |
| Windows Cloud Files Filter Loaded by Uncommon Process | Anomaly | NULL | Sysmon EventID 7 |
| Windows KrbRelayUp Service Creation | TTP | NULL | Windows Event Log System 7045 |
| Windows MsMpEng Writing to System32 | TTP | NULL | Sysmon EventID 15, Sysmon EventID 11 |
| Windows Remote Create Service | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Service Create Kernel Mode Driver | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Service Create RemComSvc | Anomaly | NULL | Windows Event Log System 7045 |
| Windows Service Create with Tscon | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Service Created Within Public Path | TTP | NULL | Windows Event Log System 7045 |
| Windows Service Creation on Remote Endpoint | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Service Initiation on Remote Endpoint | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Suspicious Driver Loaded Path | TTP | NULL | Sysmon EventID 6 |
| Windows Vulnerable Driver Installed | TTP | NULL | Windows Event Log System 7045 |
| Windows Vulnerable Driver Loaded | Hunting | NULL | Sysmon EventID 6 |
| XMRIG Driver Loaded | TTP | NULL | Sysmon EventID 6 |
| Used by | Procedure example |
|---|---|
| GroupAgrius | Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence. |
| GroupAPT19 | An APT19 Port 22 malware variant registers itself as a service. |
| GroupAPT3 | APT3 has a tool that creates a new service for persistence. |
| GroupAPT32 | APT32 modified Windows Services to ensure PowerShell scripts were loaded on the system. APT32 also creates a Windows service to establish persistence. |
| GroupAPT38 | APT38 has installed a new Windows service to establish persistence. |
| GroupAPT41 | APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike. |
| GroupAquatic Panda | Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change. |
| GroupBlackByte | BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines. |
| Used by | Procedure example |
|---|---|
| MalwareAnchor | Anchor can establish persistence by creating a service. |
| MalwareAppleJeus | AppleJeus can install itself as a service. |
| MalwareAttor | Attor's dispatcher can establish persistence by registering a new service. |
| MalwareAuditCred | AuditCred is installed as a new service on the system. |
| MalwareBankshot | Bankshot can terminate a specific process by its process id. |
| MalwareBBSRAT | BBSRAT can modify service configurations. |
| MalwareBisonal | Bisonal has been modified to be used as a Windows service. |
| MalwareBitPaymer | BitPaymer has attempted to install itself as a service to maintain persistence. |
View all 109 software examples
| Used by | Procedure example |
|---|---|
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary. |
| CampaignAPT41 DUST | APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors modified the `IKEEXT` and `PrintNotify` Windows services for persistence. |
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors created a service named Visual Studio Code Service to run Visual Studio code. |
| CampaignOperation Honeybee | During Operation Honeybee, threat actors installed DLLs and backdoors as Windows services. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.