Cross-source coverage
T1035 / ATT&CK
Service Execution
ATT&CK has retired this technique. Rules still tag it; the current id is T1569.002 System Services: Service Execution.
7 rules across 1 source.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may execute a binary, command, or script via a method that interacts with Windows services, such as the Service Control Manager. This can be done by either creating a new service or modifying an existing service. This technique is the execution used in conjunction with New Service and Modify Existing Service during service persistence or privilege escalation.
- Tactics
- Execution
- Platforms
- Windows
- Telemetry
- —
chronicle/detection-rules
7 rules| Detection | Severity | Format |
|---|---|---|
| hidden_cobra_fastcash_malware_sysmon | Undefined | YARA-L |
| possible_cobaltstrike_psexec_filenames_via_audit | Undefined | YARA-L |
| possible_cobaltstrike_psexec_filenames_via_audit_part_1 | Undefined | YARA-L |
| psexec_service_start | Undefined | YARA-L |
| psexec_tool_execution | Undefined | YARA-L |
| smbexecpy_service_installation | Undefined | YARA-L |
| wastedlocker_ransomware_hunting_credential_dumping | Undefined | YARA-L |