Sub-technique of T1569 System Services.View on attack.mitre.org
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (services.exe) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as sc.exe and Net.
PsExec can also be used to execute commands or payloads via a temporary Windows service created through the service control manager API. Tools such as PsExec and sc.exe can accept remote servers as arguments and may be used to conduct remote execution.
Adversaries may leverage these mechanisms to execute malicious content. This can be done by either executing a new or modified service. This technique is the execution used in conjunction with Windows Service during service persistence or privilege escalation.
Rules on DetectionCode tagged with T1569.002.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect Renamed PSExec | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Excessive Usage Of SC Service Utility | Anomaly | NULL | Sysmon EventID 1 |
| First Time Seen Running Windows Service | Anomaly | NULL | Windows Event Log System 7036 |
| Linux Auditd Service Started | Anomaly | NULL | Linux Auditd Proctitle |
| Malicious Powershell Executed As A Service | TTP | NULL | Windows Event Log System 7045 |
| Windows ScManager Security Descriptor Tampering Via Sc.EXE | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Service Create SliverC2 | TTP | NULL | Windows Event Log System 7045 |
| Windows Service Created with Suspicious Service Name | Anomaly | NULL | Windows Event Log System 7045 |
| Windows Service Created with Suspicious Service Path | TTP | NULL | Windows Event Log System 7045 |
| Windows Service Execution RemCom | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Snake Malware Service Create | TTP | NULL | Windows Event Log System 7045 |
| Used by | Procedure example |
|---|---|
| GroupAPT32 | APT32's backdoor has used Windows services as a way to execute its malicious payload. |
| GroupAPT38 | APT38 has created new services or modified existing ones to run executables, commands, or scripts. |
| GroupAPT39 | APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes. |
| GroupAPT41 | APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader. |
| GroupBlackByte | BlackByte created malicious services for ransomware execution. |
| GroupBlue Mockingbird | Blue Mockingbird has executed custom-compiled XMRIG miner DLLs by configuring them to execute via the "wercplsupport" service. |
| GroupChimera | Chimera has used PsExec to deploy beacons on compromised systems. |
| GroupFIN6 | FIN6 has created Windows services to execute encoded PowerShell commands. |
| Used by | Procedure example |
|---|---|
| MalwareAnchor | Anchor can create and execute services to load its payload. |
| MalwareAttor | Attor's dispatcher can be executed as a service. |
| MalwareBad Rabbit | Bad Rabbit drops a file named |
| MalwareBBSRAT | BBSRAT can start, stop, or delete services. |
| MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware executes as a service when deployed. |
| ToolBrute Ratel C4 | Brute Ratel C4 can create Windows system services for execution. |
| MalwareClambling | Clambling can create and start services on a compromised host. |
| MalwareCobalt Strike | Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services. |
| Used by | Procedure example |
|---|---|
| CampaignAPT41 DUST | APT41 DUST used Windows services to execute DUSTPAN. |
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the winsw tool to deploy a Visual Studio code executable as a Windows service. |
| CampaignOperation Honeybee | During Operation Honeybee, threat actors ran |
| CampaignOperation Wocao | During Operation Wocao, threat actors created services on remote systems for execution purposes. |
| CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged PsExec for command execution and used `services.exe` to disable Microsoft Defender via Registry keys. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.