.. / Sc.exe
Star

Used by Windows to manage services


Paths:


Resources:
https://oddvar.moe/2018/04/11/putting-data-in-alternate-data-streams-and-how-to-execute-it-part-2/

Acknowledgement:
Oddvar Moe - @oddvarmoe


Detection:
Services that gets created



Alternate data streams

Creates a new service and executes the file stored in the ADS.
sc create evilservice binPath="\"c:\\ADS\\file.txt:cmd.exe\" /c echo works > \"c:\ADS\works.txt\"" DisplayName= "evilservice" start= auto\ & sc start evilservice
Usecase:Execute binary file hidden inside an alternate data stream
Privileges required:User
OS:Windows vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Mitre:T1096