Cross-source coverage

T1031 / ATT&CK

Modify Existing Service

ATT&CK has retired this technique. Rules still tag it; the current id is T1543.003 Create or Modify System Process: Windows Service.

2 rules · 1 family across 1 source.

2 deprecated hidden · include

From MITRE ATT&CK 19.2

Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Registry. Service configurations can be modified using utilities such as sc.exe and Reg.

Adversaries can modify an existing service to persist malware on a system by using system utilities or by using custom tools to interact with the Windows API. Use of existing services is a type of Masquerading that may make detection analysis more challenging. Modifying existing services may interrupt their functionality or may enable services that are disabled or otherwise not commonly used.

Adversaries may also intentionally corrupt or kill services to execute malicious recovery programs/commands.

Tactics
Persistence
Platforms
Windows
Telemetry

socfortress/Wazuh-Rules

2 rules · 1 family
Detection Severity Format
Sysmon - Event 1: Process creation · Modify Existing Service (T1031) 2 variants Low Wazuh XML
Sysmon - Event 1: Process creation · Modify Existing Service (T1031) 2 variants Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.