.. /Sc.exe
Star

Used by Windows to manage services


Paths:

Resources:
Acknowledgements:

Detection:

Alternate data streams

Creates a new service and executes the file stored in the ADS.
sc create evilservice binPath="\"c:\\ADS\\file.txt:cmd.exe\" /c echo works > \"c:\ADS\works.txt\"" DisplayName= "evilservice" start= auto\ & sc start evilservice
Usecase: Execute binary file hidden inside an alternate data stream
Privileges required: User
OS: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
MITRE ATT&CK®: T1564.004



Modifies an existing service and executes the file stored in the ADS.
sc config <existing> binPath="\"c:\\ADS\\file.txt:cmd.exe\" /c echo works > \"c:\ADS\works.txt\"" & sc start <existing>
Usecase: Execute binary file hidden inside an alternate data stream
Privileges required: User
OS: Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10, Windows 11
MITRE ATT&CK®: T1564.004