1200KM / simulation
T1543.003 Windows Service — Attack Simulation
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry. Adversaries may install a new service or modify an…
Technique description
Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence. When Windows boots up, it starts programs or applications called services that perform background system functions. Windows service configuration information, including the file path to the service's executable or recovery programs/commands, is stored in the Windows Registry. Adversaries may install a new service or modify an…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Modify Service to Run Arbitrary Binary (Powershell)
Procedure 1f896ce4-8070-4959-8a25-2658856a70c9; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Service Installation PowerShell
Procedure 491a4af6-a521-4b74-b23b-f7b3f1ee9e77; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Service Installation CMD
Procedure 981e2942-e433-44e9-afc1-8c957a1496b6; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modify Fax service to run PowerShell
Procedure ed366cde-7d12-49df-a833-671904770b9f; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- TinyTurla backdoor service w64time
Procedure ef0581fd-528e-4662-87bc-4c2affb86940; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Remote Service Installation CMD
Procedure fb4151a2-db33-4f8c-b7f8-78ea8790f961; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- Carbanak · G0008
- APT3 · G0022
- Threat Group-3390 · G0027
- Lotus Blossom · G0030
- Lazarus Group · G0032
- FIN7 · G0046
- OilRig · G0049
- APT32 · G0050
- PROMETHIUM · G0056
- APT19 · G0073
- Cobalt Group · G0080
- Tropic Trooper · G0081
- APT38 · G0082
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- DarkVishnya · G0105
- Blue Mockingbird · G0108
- TeamTNT · G0139
- Aquatic Panda · G0143
- Earth Lusca · G1006
- Cinnamon Tempest · G1021
- Agrius · G1030
- BlackByte · G1043
- Medusa Group · G1051
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.