1200KM / simulation
T1569.002 Service Execution — Attack Simulation
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (services.exe) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as sc.exe and Net. PsExec can also be used to execute commands or payloads via a temporary Windows service created through the service control…
Technique description
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads. The Windows service control manager (services.exe) is an interface to manage and manipulate services. The service control manager is accessible to users via GUI components as well as system utilities such as sc.exe and Net. PsExec can also be used to execute commands or payloads via a temporary Windows service created through the service control…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Pipe Creation - PsExec Tool Execution From Suspicious Locations
Procedure 004a5d68-627b-452d-af3d-43bd1fc75a3b; elevation required; cleanup not declared. Not executed or individually validated.
- Execute a Command as a Service
Procedure 2382dee2-a75f-49aa-9378-f52df6ed3fb1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- BlackCat pre-encryption cmds with Lateral Movement
Procedure 31eb7828-97d7-4067-9c1e-c6feb85edc4b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Use PsExec to execute a command on a remote host
Procedure 873106b7-cfed-454b-8680-fa9f6400431c; elevation required; cleanup not declared. Not executed or individually validated.
- Use RemCom to execute a command on a remote host
Procedure a5d8cdeb-be90-43a9-8b26-cc618deac1e0; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Snake Malware Service Create
Procedure b8db787e-dbea-493c-96cb-9272296ddc49; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Modifying ACL of Service Control Manager via SDET
Procedure bf07f520-3909-4ef5-aa22-877a50f2f77b; elevation required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.