Windows Service and SCM Abuse: Persistence, Privilege Escalation, and Lateral Movement
A comprehensive map of the Windows Service Control Manager (SCM) attack surface: new service creation (T1543.003), ServiceDll hijack, unquoted path / weak binary and registry ACL exploitation (T1574.009-011), PsExec-style transient service for lateral movement (T1569.002). EID 7045/4697, Sysmon EID 13 detection, and Sigma correlations for SOC and red/purple teams.
Active exploitation warning
The following vulnerabilities referenced in this content are under active exploitation in the CISA KEV catalog:
Source: CISA KEV ·
Swipe or use the arrows to move between sections
Zafiyet (Vulnerability)
Tehdit bağlamı, zafiyet ve istismar senaryosu
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →Prevention & Hardening
Savunma teknolojileri, policy ve sertleştirme
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →Detection
Davranış, loglama ve detection kuralları
This section is not open yet
Titles and summaries are free. The detail of this section is not published yet. You can request the offline comparison tool for the open environments with a company email.
Request the offline tool →