kevmap

Techniques › T1569

T1569 System Services

execution — Windows, macOS, Linux · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
4
Sigma rules tagged attack.t1569
0
KEV CVEs mapped here
<p>Adversaries may abuse system services or daemons to execute commands or programs. Adversaries can execute malicious content by interacting with or creating services either locally or remotely. Many services are set to run at boot, which can aid in achieving persistence (Create or Modify System Process), but adversaries can also abuse services for one-time or temporary execution.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1569

Author: Florian Roth (Nextron Systems), KevTheHermit, fuzzyf10w, Tim Shelton · 2021-06-30 (modified 2022-11-15) · logsource: product=windows service=printservice-admin · 4e64668a-4da1-49f5-a8df-9e2d5b866718
Detects events of driver load errors in print service logs that could be a sign of successful exploitation attempts of print spooler vulnerability CVE-2021-1675
Techniques: T1569
CVE tags: CVE-2021-1675
Psexec Execution mediumtest
Author: omkar72 · 2020-10-30 (modified 2023-02-28) · logsource: product=windows category=process_creation · 730fc21b-eaff-474b-ad23-90fd265d4988
Detects user accept agreement execution in psexec commandline
Techniques: T1569T1021
Author: INIT_6 · 2021-07-02 (modified 2022-10-05) · logsource: product=windows service=security · 8fe1c584-ee61-444b-be21-e9054b229694
Detects remote printer driver load from Detailed File Share in Security logs that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675 and CVE-2021-34527
Techniques: T1569
CVE tags: CVE-2021-1675CVE-2021-34527
Author: Florian Roth (Nextron Systems) · 2021-07-01 (modified 2022-10-09) · logsource: product=windows service=printservice-operational · f34d942d-c8c4-4f1f-b196-22471aecf10a
Detects driver load events print service operational log that are a sign of successful exploitation attempts against print spooler vulnerability CVE-2021-1675
Techniques: T1569
CVE tags: CVE-2021-1675

Sub-techniques

IDNameSigma rulesKEV CVEs
T1569.001Launchctl10
T1569.002Service Execution431
T1569.003Systemctl00