Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Adversaries may abuse system services or daemons to execute commands or programs.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-13 | ✗→✓ | ▲ Improved | 13% | 0% |
| case-11 | ✗→✓ | ▲ Improved | -50% | 0% |
| case-12 | ✗→✓ | ▲ Improved | -35% | 0% |
| case-19 | ✗→✓ | ▲ Improved | -34% | 0% |
| case-21 | ✗→✓ | ▲ Improved | -50% | 0% |
Adversaries may abuse system services or daemons to execute commands or programs. Adversaries can execute malicious content by interacting with or creating services either locally or remotely. Many services are set to run at boot, which can aid in achieving persistence (Create or Modify System Process), but adversaries can also abuse services for one-time or temporary execution.
Platforms: Windows, macOS, Linux
> Note: No Atomic Red Team tests available for this technique. See Atomic Red Team GitHub for updates.
Ensure that permissions disallow services that run at a higher permissions level from being created or interacted with by a user with a lower permission level.
Prevent users from installing their own launch agents or launch daemons.
On Windows 10, enable Attack Surface Reduction (ASR) rules to block processes created by PsExec from running.
Ensure that high permission level service binaries cannot be replaced or modified by users with a lower permission level.
| Finding | Severity | Impact | | ------------------------------------ | -------- | --------- | | System Services technique applicable | Low | Execution |
| CWE ID | Title | | ------ | -------------------------------------- | | CWE-94 | Improper Control of Generation of Code |
Other measured skills in the registry, with their headline benchmark lift.