Windows Service

T1543.003

Sub-technique of T1543 Create or Modify System Process.View on attack.mitre.org

About this technique

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry.

Adversaries may install a new service or modify an existing service to execute at startup in order to persist on a system. Service configurations can be set or modified using system utilities (such as sc.exe), by directly modifying the Registry, or by interacting directly with the Windows API.

Adversaries may also use services to install and execute malicious drivers. For example, after dropping a driver file (ex: `.sys`) to disk, the payload can be loaded and registered via Native API functions such as `CreateServiceW()` (or manually via functions such as `ZwLoadDriver()` and `ZwSetValueKey()`), by creating the required service Registry values (i.e. Modify Registry), or by using command-line utilities such as `PnPUtil.exe`. Adversaries may leverage these drivers as Rootkits to hide the presence of malicious activity on a system. Adversaries may also load a signed yet vulnerable driver onto a compromised machine (known as "Bring Your Own Vulnerable Driver" (BYOVD)) as part of Exploitation for Privilege Escalation.

Services may be created with administrator privileges but are executed under SYSTEM privileges, so an adversary may also use a service to escalate privileges. Adversaries may also directly start services through Service Execution.

To make detection analysis more challenging, malicious services may also incorporate Masquerade Task or Service (ex: using a service and/or payload name related to a legitimate OS or benign software component). Adversaries may also create ‘hidden’ services (i.e., Hide Artifacts), for example by using the `sc sdset` command to set service permissions via the Service Descriptor Definition Language (SDDL). This may hide a Windows service from the view of standard service enumeration methods such as `Get-Service`, `sc query`, and `services.exe`.

Detection rules63

Rules on DetectionCode tagged with T1543.003.

Sigma38

RuleLevelLog source
CobaltStrike Service Installations - Systemcriticalwindows / NULL
Moriya Rootkit - Systemcriticalwindows / NULL
Allow Service Access Using Security Descriptor Tampering Via Sc.EXEhighwindows / process_creation
CobaltStrike Service Installations - Securityhighwindows / NULL
Deny Service Access Using Security Descriptor Tampering Via Sc.EXEhighwindows / process_creation
Devcon Execution Disabling VMware VMCI Devicehighwindows / process_creation
Driver Load From A Temporary Directoryhighwindows / driver_load
Malicious Driver Loadhighwindows / driver_load
Potential CobaltStrike Service Installations - Registryhighwindows / registry_set
ProcessHacker Privilege Elevationhighwindows / NULL
PSEXEC Remote Execution File Artefacthighwindows / file_event
PUA - Kernel Driver Utility (KDU) Executionhighwindows / process_creation
Service Installation with Suspicious Folder Patternhighwindows / NULL
Sliver C2 Default Service Installationhighwindows / NULL
Suspicious New Service Creationhighwindows / process_creation

Splunk25

RuleTypeRiskData source
CMD Echo Pipe - EscalationTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Impacket Lateral Movement Commandline ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Impacket Lateral Movement smbexec CommandLine ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Impacket Lateral Movement WMIExec Commandline ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Possible Lateral Movement PowerShell SpawnAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2
Randomly Generated Windows Service NameHuntingNULLWindows Event Log System 7045
Sc exe Manipulating Windows ServicesTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Services LOLBAS Execution Process SpawnTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Suspicious Driver Loaded PathTTPNULLSysmon EventID 6
Windows Admin Password Changed by Non-AdminTTPNULLWindows Event Log Security 4723
Windows Bluetooth Service Installed From Uncommon LocationAnomalyNULLWindows Event Log System 7045
Windows Cloud Files Filter Loaded by Uncommon ProcessAnomalyNULLSysmon EventID 7
Windows KrbRelayUp Service CreationTTPNULLWindows Event Log System 7045
Windows MsMpEng Writing to System32TTPNULLSysmon EventID 15, Sysmon EventID 11
Windows Remote Create ServiceAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups26

Show 2 more

Software109

Show 85 more

Campaigns5

Procedure examples140

Groups26

Used byProcedure example
GroupAgrius

Agrius has deployed IPsec Helper malware post-exploitation and registered it as a service for persistence.

GroupAPT19

An APT19 Port 22 malware variant registers itself as a service.

GroupAPT3

APT3 has a tool that creates a new service for persistence.

GroupAPT32

APT32 modified Windows Services to ensure PowerShell scripts were loaded on the system. APT32 also creates a Windows service to establish persistence.

GroupAPT38

APT38 has installed a new Windows service to establish persistence.

GroupAPT41

APT41 modified legitimate Windows services to install malware backdoors. APT41 created the StorSyncSvc service to provide persistence for Cobalt Strike.

GroupAquatic Panda

Aquatic Panda created new Windows services for persistence that masqueraded as legitimate Windows services via name change.

GroupBlackByte

BlackByte modified multiple services on victim machines to enable encryption operations. BlackByte has installed tools such as AnyDesk as a service on victim machines.

View all 26 groups examples

Software109

Used byProcedure example
MalwareAnchor

Anchor can establish persistence by creating a service.

MalwareAppleJeus

AppleJeus can install itself as a service.

MalwareAttor

Attor's dispatcher can establish persistence by registering a new service.

MalwareAuditCred

AuditCred is installed as a new service on the system.

MalwareBankshot

Bankshot can terminate a specific process by its process id.

MalwareBBSRAT

BBSRAT can modify service configurations.

MalwareBisonal

Bisonal has been modified to be used as a Windows service.

MalwareBitPaymer

BitPaymer has attempted to install itself as a service to maintain persistence.

View all 109 software examples

Campaigns5

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team used an arbitrary system service to load at system boot for persistence for Industroyer. They also replaced the ImagePath registry value of a Windows service with a new backdoor binary.

CampaignAPT41 DUST

APT41 DUST used Windows Services with names such as `Windows Defend` for persistence of DUSTPAN.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors modified the `IKEEXT` and `PrintNotify` Windows services for persistence.

CampaignOperation Digital Eye

During Operation Digital Eye, threat actors created a service named Visual Studio Code Service to run Visual Studio code.

CampaignOperation Honeybee

During Operation Honeybee, threat actors installed DLLs and backdoors as Windows services.

References7

  1. Crowdstrike DriveSlayer February 2022 Open source
    Thomas, W. et al. (2022, February 25). CrowdStrike Falcon Protects from New Wiper Malware Used in Ukraine Cyberattacks. Retrieved March 25, 2022.
  2. ESET InvisiMole June 2020 Open source
    Hromcova, Z. and Cherpanov, A. (2020, June). INVISIMOLE: THE HIDDEN PART OF THE STORY. Retrieved July 16, 2020.
  3. SANS 1 Open source
    Joshua Wright. (2020, October 13). Retrieved March 22, 2024.
  4. SANS 2 Open source
    Joshua Wright. (2020, October 14). Retrieved March 22, 2024.
  5. Symantec W.32 Stuxnet Dossier Open source
    Nicolas Falliere, Liam O. Murchu, Eric Chien. (2011, February). W32.Stuxnet Dossier. Retrieved December 7, 2020.
  6. TechNet Services Open source
    Microsoft. (n.d.). Services. Retrieved June 7, 2016.
  7. Unit42 AcidBox June 2020 Open source
    Reichel, D. and Idrizovic, E. (2020, June 17). AcidBox: Rare Malware Repurposing Turla Group Exploit Targeted Russian Organizations. Retrieved March 16, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.