Umbra Wiki technique technique/T1569.002
Back to wiki

T1569.002 — Service Execution

provenance: imported · ATT&CK: T1569.002

T1569.002: Service Execution

MITRE ATT&CK® Enterprise technique

Tactics Execution
Platforms Windows
Permissions required
Version 1.3
Parent technique T1569

Description

Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>services.exe</code>) is an interface to manage and manipulate services.(Citation: Microsoft Service Control Manager) The service control manager is accessible to users via GUI components as well as system utilities such as <code>sc.exe</code> and Net.

PsExec can also be used to execute commands or payloads via a temporary Windows service created through the service control manager API.(Citation: Russinovich Sysinternals) Tools such as PsExec and <code>sc.exe</code> can accept remote servers as arguments and may be used to conduct remote execution.

Adversaries may leverage these mechanisms to execute malicious content. This can be done by either executing a new or modified service. This technique is the execution used in conjunction with Windows Service during service persistence or privilege escalation.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1569/002
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/