Cross-source coverage

T1035 / ATT&CK

Service Execution

ATT&CK has retired this technique. Rules still tag it; the current id is T1569.002 System Services: Service Execution.

7 rules across 1 source.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may execute a binary, command, or script via a method that interacts with Windows services, such as the Service Control Manager. This can be done by either creating a new service or modifying an existing service. This technique is the execution used in conjunction with New Service and Modify Existing Service during service persistence or privilege escalation.

Tactics
Execution
Platforms
Windows
Telemetry

chronicle/detection-rules

7 rules
Detection Severity Format
hidden_cobra_fastcash_malware_sysmon Undefined YARA-L
possible_cobaltstrike_psexec_filenames_via_audit Undefined YARA-L
possible_cobaltstrike_psexec_filenames_via_audit_part_1 Undefined YARA-L
psexec_service_start Undefined YARA-L
psexec_tool_execution Undefined YARA-L
smbexecpy_service_installation Undefined YARA-L
wastedlocker_ransomware_hunting_credential_dumping Undefined YARA-L

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.