FORENSIA

ATT&CK · T1569.002 · sub-technique

Service Execution

Tactics: execution

About

Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (<code>services.exe</code>) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as <code>sc.exe</code> and Net. PsExec can also be used to execute commands or payloads via a temporary Windows service created through the service control manager API. Tools such as PsExec and <code>sc.exe</code> can accept remote servers as arguments and may be used to conduct remote execution. Adversaries may leverage these mechanisms to execute malicious content. This can be done by either executing a new or modified service. This technique is the execution used in conjunction with Windows Service during service persistence or privilege escalation.

Platforms: WindowsParent: T1569 System ServicesMITRE ATT&CK ↗

Used by actors

16 known groups

Software

51 malware/tools implement this

PsExecgh0st RATNetNet CrawlerxCmdBBSRATShamoonWinnti for WindowsCobalt StrikeRemoteCMDWingbirdWinexePupyHydraqProxysvcKoadicInvisiMoleImpacketEmpireOlympic DestroyerNotPetyaHOPLIGHTPoshC2HyperBroZxShellAttorOkrumLoudMinerNetwalkerRagnar LockerStrongPityAnchorSLOTHFULMEDIAPysaBad RabbitWastedLockerClamblingSysUpdatePandoraTinyTurlaWhisperGateHermeticWiperHermeticWizardMafaldaBrute Ratel C4DarkGateIPsec HelperDEADWOODBlackByte 2.0 RansomwareLockBit 3.0Embargo

Corpus indicators tagged with this technique

217 indicators in the corpus carry T1569.002.

IndicatorTypeFamilySevSrc
cve-2025-1055cveransomware853
cve-2023-52271cveransomware853
cve-2025-61155cveransomware853
cve-2026-4368cveransomware851
d26bfb0147f60dc6500a9298d521ee67b49daaf4b8f8be54e7cc8fd86a597570hashransomware801
6cd349eda0fa6c8b274a0920852c68f8b727afea1fdbc69ad183cef05d9cf141hashransomware801
d65120291dee76c694f8bea54841f7f68329b499b28f4aee5ea5c9369a7432cbhashransomware801
acce811c4fc2a6e3fddd4231e386f1648ca44f039d2d275316bc0a0fc96e0af4hashransomware801
d0da2832ae1e13a98f7ce7e33a66c1b0d9797b81f69ece134e4462ea55ac923ehashransomware803
5cc212f84d2bf3fbab165aaf09b16e00fcf2f1ccd880d24b14404c53dcdbf241hashransomware801
6bf155b269d452f3c3b62832b27bbebe4da436e228dbf521155b1d5989e3743fhashransomware801
7f37351979c249417cb180b4ede0ed17e5fe2a1f08add4d72606b589f8fdb245hashransomware801
8d1a22c430252f29611766b8e4a82af0fba60d609246463466b384d6d4793df4hashransomware801
90e46e89fec2108a1cb4850bb33e3563e92a14d04e1e613ac8c9311f152d294chashransomware801
dc9938f51150d13a69fc25f3f19052eacb1bf0a086fd5cf39762501fb3ddd7dahashransomware801
31800380c359143ae82c4f9011eee653dd22443d03d6a499148203bbfc275502hashransomware801
bf8c45e5aa9551a17eefbd1d179422c32b4309c47ee9a3f315bb80ed6d4f7efchashransomware801
f6a01d0246ce31faf6938ea488086d4358505405a4ef5c5faa482e79e92cb347hashransomware801
24f6c0ca39b2a5593086ff56d818ddfbde121f8e44d54faa762e510397dc9db7hashransomware801
5af1dae21425dda8311a2044209c308525135e1733eeff5dd20649946c6e054csha256ransomware802
cb747c0134f99d5033bac6e966864e2435a2a94244ca8e3f614f4992df93ff10sha256ransomware802
03dd0efa84d145d7d4ed8e240267e5c5hashransomware801
1898d056463284d849801cbdea6a3dec6c9f568f01569912c3868a5eea9a5449hashransomware801
1d10d8f5a420d0e4683b4cb40bcf0c984d1e7ea1f3b4442a00a525584632ac11hashransomware801
265a8e89464e32b22553ef16edbab703da7176a7hashransomware801
589d9480fbfec2d8e61638eb0b537183d0f9977411fd1d2c0f8eb611feebe880hashransomware801
60aeb9f7bccf377ff02ed64783e66a62c0f976878d9729b067bc7e5b0b9da9d6hashransomware801
70331fdf528f4f5b75b5e30427e379bc88aa05b4hashransomware801
765508aa2ec6a1b73a76a23f4fa559d32355622748c91a46ed7b315eae2ee60ahashransomware801
97aebda5482899fef84a24e456bff055acaa47e5ab4029f768d9e0c62a660ce2hashransomware801

Showing the top 30 by severity of 217.