-
Notifications
You must be signed in to change notification settings - Fork 245
New Windows Service
h4wkst3r edited this page Jan 5, 2020
·
2 revisions
This persistence technique creates and registers a new service. In this module, you will supply a service name, and system command to execute by the service.
Admin privileges
- -c - command to execute
- -a - arguments to command to execute (if applicable)
- -n - service name
- -m - method (add, remove, check, list)
- Service is created and registered that will run automatically upon boot up and will run as SYSTEM
- Needs to be ran as admin user in high integrity process (safe check for this)
- Service is deleted via the Service Control Manager (SCM).
- Needs to be ran as admin user in high integrity process (safe check for this)
SharPersist -t service -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -n "Some Service" -m add
SharPersist -t service -n "Some Service" -m remove
SharPersist -t service -c "C:\Windows\System32\cmd.exe" -a "/c calc.exe" -n "Some Service" -m check
SharPersist -t service -m list
SharPersist -t service -m list -n "Some Service"