FORENSIA

ATT&CK · T1543.003 · sub-technique

Windows Service

Tactics: persistence, privilege-escalation

About

Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry. Adversaries may install a new service or modify an existing service to execute at startup in order to persist on a system. Service configurations can be set or modified using system utilities (such as sc.exe), by directly modifying the Registry, or by interacting directly with the Windows API. Adversaries may also use services to install and execute malicious drivers. For example, after dropping a driver file (ex: `.sys`) to disk, the payload can be loaded and registered via Native API functions such as `CreateServiceW()` (or manually via functions such as `ZwLoadDriver()` and `ZwSetValueKey()`), by creating the required service Registry values (i.e. Modify Registry), or by using command-line utilities such as `PnPUtil.exe`. Adversaries may leverage these drivers as Rootkits to hide the presence of malicious activity on a system. Adversaries may also load a signed yet vulnerable driver onto a compromised machine (known as "Bring Your Own Vulnerable Driver" (BYOVD)) as part of Exploitation for Privilege Escalation. Services may be created with administrator privileges but are executed under SYSTEM privileges, so an adversary may also use a service to escalate privileges. Adversaries may also directly start services through Service Execution. To make detection analysis more challenging, malicious services may also incorporate Masquerade Task or Service (ex: using a service and/or payload name related to a legitimate OS or benign software component). Adversaries may also create ‘hidden’ services (i.e., Hide Artifacts), for example by using the `sc sdset` command to set service permissions via the Service Descriptor Definition Language (SDDL). This may hide a Windows service from the view of standard service enumeration methods such as `Get-Service`, `sc query`, and `services.exe`.

Used by actors

26 known groups

Software

109 malware/tools implement this

TinyZBotPoisonIvyPlugXUroburosDyrePsExecgh0st RATDuquJHUHUGITCozyCarCosmicDukehcdLoaderSakulaEliseEmissaryZLibBlackEnergyNidiranBBSRATShamoonWinnti for WindowsStreamExMoonWindCobalt StrikeTDTESSRawPOSReaverWingbirdVolgmerFALLCHILLFinFisherPowerSploitHydraqBribaNaidWiarpNerexZeroTKwampirsBankshotInnaputRATInvisiMoleCatchamasTYPEFRAMEKazuarTrickBotBisonalRemcosCarbonGreyEnergyExaramel for WindowsSeasaltAuditCredzwShellKONNIEmpireWannaCryEmotetUrsnifKeyBoyZxShellAttorOkrumShimRatLoudMinerRagnar LockerStrongPityGoldenSpyRDATPipeMonAnchorSLOTHFULMEDIATEARDROPDtrackBitPaymerAppleJeusStuxnetIndustroyerConfickerWastedLockerCubaRainyDayNebulaeQakBotClamblingSysUpdatePandoraThreatNeedleGelsemiumSILENTTRINITYHermeticWiperPingPullDCSrvSTARWHALEFunnyDreamSUGARUSHBlack BastaNightClubSamuraiNinjaDUSTPANLockBit 3.0HannotogBOOKWORMSplatDropperCorKLOGTONESHELLMedusa RansomwareEmbargo

Corpus indicators tagged with this technique

426 indicators in the corpus carry T1543.003.

IndicatorTypeFamilySevSrc
cve-2025-34054cve854
cve-2023-44976cveransomware852
cve-2016-0638cvephishing851
cve-2016-15047cve854
cve-2026-4368cveransomware851
cve-2021-27137cve858
5e97f7c17bf0466355be0438c7cc3e2e4d125e31368f2fbcb8e1d79cb97f137asha256phishing802
9570f77a5e1511869f4e554e7166df9fde081f2583e293c2569621792ed7d9c9hashsupply_chain801
7e142c8fa614cc39d0453aa648b12209821c6bcbb77ee02094f70161b40d50aesha256phishing802
f88d2b5c3b885ad5a9c1c44551bccc60hashransomware802
242038139842ec79ec1044c64eb0804ahashransomware802
c277ae5a4dd62f51de5278790796cd2700de7f77ea17762e97729f27872d076bsha256ransomware801
5a00485968679dc0ed6d80b659f48287603864c223e952918d2c2aaddfa2d280sha256phishing802
1c0924f5711a24821921de5ad822213bhashransomware802
123e80a34508c4dede7cc70e76931fcchash803
9ca9432b0d29204cb5420a1a6b01533d4552130c2a8a5ecd7837efadefb4a046sha256ransomware801
09d0517a1f69feff8186655ae3b567e0hashransomware802
625b6535321d58bb5c613e85332bf731hash803
7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237sha256ransomware801
873f1277a42de5c82f869459e7fb7c94554a642bhash803
681075027553546c119ec447eb8df84633dcffcehash803
5398b7eaa94f0ee570b1c5642b559047hashransomware802
f4d77958a12a0778283d3e679b24b18f82e332c4hash803
0b1870d57221eec6f3bbef648e71a724hashransomware802
b8eed63ab9cbdca494f26a6f66bfd4a0a693b3f0hash803
b36968b98046d1b033d84f292e7ca1cbhashransomware802
eead44c0af7ddb12cece1a6125cf213bab3c22511cd59aff9d63dcfddb7d4386hash804
6dfef58ef68fb7965a23da8be3141af9hashransomware802
9c44bc9373377831c45dd0ac2661a28ehash803
1344e6bc51cea35befb4adff7a25899bhashransomware802

Showing the top 30 by severity of 426.