#T1035 Service Execution

Technique

  • Tactics: Execution
  • Description:

    Adversaries may execute a binary, command, or script via a method that interacts with Windows services, such as the Service Control Manager. This can be done by either creating a new service or modifying an existing service. This technique is the execution used in conjunction with [New Service](https://attack.mitre.org/techniques/T1050) and [Modify Existing Service](https://attack.mitre.org/techniques/T1031) during service persistence or privilege escalation.

  • First Seen: Operation In(ter)ception: Aerospace and military companies in the crosshairs of cyberspies • 2020-06-17
MITRE ATT&CK

Tagged Reports

« Back