Service Execution

T1569.002

Sub-technique of T1569 System Services.View on attack.mitre.org

About this technique

Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (services.exe) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as sc.exe and Net.

PsExec can also be used to execute commands or payloads via a temporary Windows service created through the service control manager API. Tools such as PsExec and sc.exe can accept remote servers as arguments and may be used to conduct remote execution.

Adversaries may leverage these mechanisms to execute malicious content. This can be done by either executing a new or modified service. This technique is the execution used in conjunction with Windows Service during service persistence or privilege escalation.

Detection rules50

Rules on DetectionCode tagged with T1569.002.

Sigma39

RuleLevelLog source
CobaltStrike Service Installations - Systemcriticalwindows / NULL
HackTool - SharpUp PrivEsc Tool Executioncriticalwindows / process_creation
CobaltStrike Service Installations - Securityhighwindows / NULL
Credential Dumping Tools Service Execution - Securityhighwindows / NULL
Credential Dumping Tools Service Execution - Systemhighwindows / NULL
HackTool Service Registration or Executionhighwindows / NULL
Metasploit Or Impacket Service Installation Via SMB PsExechighwindows / NULL
Potential CobaltStrike Service Installations - Registryhighwindows / registry_set
PowerShell as a Service in Registryhighwindows / registry_set
PowerShell Scripts Installed as Serviceshighwindows / NULL
PowerShell Scripts Installed as Services - Securityhighwindows / NULL
ProcessHacker Privilege Elevationhighwindows / NULL
PSExec and WMI Process Creations Blockhighwindows / NULL
PUA - CsExec Executionhighwindows / process_creation
PUA - NirCmd Execution As LOCAL SYSTEMhighwindows / process_creation

Splunk11

RuleTypeRiskData source
Detect Renamed PSExecHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Excessive Usage Of SC Service UtilityAnomalyNULLSysmon EventID 1
First Time Seen Running Windows ServiceAnomalyNULLWindows Event Log System 7036
Linux Auditd Service StartedAnomalyNULLLinux Auditd Proctitle
Malicious Powershell Executed As A ServiceTTPNULLWindows Event Log System 7045
Windows ScManager Security Descriptor Tampering Via Sc.EXETTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Service Create SliverC2TTPNULLWindows Event Log System 7045
Windows Service Created with Suspicious Service NameAnomalyNULLWindows Event Log System 7045
Windows Service Created with Suspicious Service PathTTPNULLWindows Event Log System 7045
Windows Service Execution RemComTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows Snake Malware Service CreateTTPNULLWindows Event Log System 7045

Groups16

Software51

Show 27 more

Campaigns5

Procedure examples72

Groups16

Used byProcedure example
GroupAPT32

APT32's backdoor has used Windows services as a way to execute its malicious payload.

GroupAPT38

APT38 has created new services or modified existing ones to run executables, commands, or scripts.

GroupAPT39

APT39 has used post-exploitation tools including RemCom and the Non-sucking Service Manager (NSSM) to execute processes.

GroupAPT41

APT41 used svchost.exe and Net to execute a system service installed to launch a Cobalt Strike BEACON loader.

GroupBlackByte

BlackByte created malicious services for ransomware execution.

GroupBlue Mockingbird

Blue Mockingbird has executed custom-compiled XMRIG miner DLLs by configuring them to execute via the "wercplsupport" service.

GroupChimera

Chimera has used PsExec to deploy beacons on compromised systems.

GroupFIN6

FIN6 has created Windows services to execute encoded PowerShell commands.

View all 16 groups examples

Software51

Used byProcedure example
MalwareAnchor

Anchor can create and execute services to load its payload.

MalwareAttor

Attor's dispatcher can be executed as a service.

MalwareBad Rabbit

Bad Rabbit drops a file named infpub.datinto the Windows directory and is executed through SCManager and rundll.exe.

MalwareBBSRAT

BBSRAT can start, stop, or delete services.

MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware executes as a service when deployed.

ToolBrute Ratel C4

Brute Ratel C4 can create Windows system services for execution.

MalwareClambling

Clambling can create and start services on a compromised host.

MalwareCobalt Strike

Cobalt Strike can use PsExec to execute a payload on a remote host. It can also use Service Control Manager to start new services.

View all 51 software examples

Campaigns5

Used byProcedure example
CampaignAPT41 DUST

APT41 DUST used Windows services to execute DUSTPAN.

CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the winsw tool to deploy a Visual Studio code executable as a Windows service.

CampaignOperation Honeybee

During Operation Honeybee, threat actors ran sc start to start the COMSysApp as part of the service hijacking and sc stop to stop and reconfigure the COMSysApp.

CampaignOperation Wocao

During Operation Wocao, threat actors created services on remote systems for execution purposes.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors leveraged PsExec for command execution and used `services.exe` to disable Microsoft Defender via Registry keys.

References2

  1. Microsoft Service Control Manager Open source
    Microsoft. (2018, May 31). Service Control Manager. Retrieved March 28, 2020.
  2. Russinovich Sysinternals Open source
    Russinovich, M. (2014, May 2). Windows Sysinternals PsExec v2.11. Retrieved May 13, 2015.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.