daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

scmexec.md (2155B)


      1 ---
      2 title: "SCMExec"
      3 section: "Windows"
      4 sectionSlug: "windows-hardening"
      5 sourcePath: "src/windows-hardening/lateral-movement/scmexec.md"
      6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/lateral-movement/scmexec.md"
      7 sha: "188de82beb54e70956b2952367a0af91d26758b8"
      8 isIndex: false
      9 modified: true
     10 license: "CC-BY-NC-4.0"
     11 ---
     12 
     13 # SCMExec
     14 
     15 ## How It Works
     16 
     17 The Service Control Manager Remote Protocol (SCMR) is an RPC-based protocol for configuring and controlling Windows services on a remote computer. With sufficient permissions, an operator can create or reconfigure a service whose binary path contains a command and then start that service to execute the command remotely.<sup>[[1]](#references)</sup>
     18 
     19 If no service account is specified, `CreateService` uses `LocalSystem`, which has extensive local privileges. This explains the high impact of successful SCM execution. It does not inherently disable UAC or Microsoft Defender: the caller still needs remote SCM rights, and endpoint controls can inspect or block the service or payload.<sup>[[3]](#references)</sup><sup>[[4]](#references)</sup>
     20 
     21 ## Tools
     22 
     23 **SharpMove** supports authenticated remote execution through SCM and several other Windows mechanisms. The following example selects its SCM action, creates a service named `WindowsDebug`, and points it at a payload already present on the remote host.<sup>[[2]](#references)</sup>
     24 
     25 ```powershell
     26 SharpMove.exe action=scm computername=remote.host.local command="C:\windows\temp\payload.exe" servicename=WindowsDebug amsi=true
     27 ```
     28 
     29 ## References
     30 
     31 - [1] [Microsoft Open Specifications - Service Control Manager Remote Protocol overview](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-scmr/d5bd5712-fa64-44bf-9433-3651f6a5ce97)
     32 - [2] [GitHub - SharpMove](https://github.com/0xthirteen/SharpMove)
     33 - [3] [Microsoft Learn - LocalSystem account](https://learn.microsoft.com/en-us/windows/win32/services/localsystem-account)
     34 - [4] [Microsoft Learn - `CreateService` function](https://learn.microsoft.com/en-us/windows/win32/api/winsvc/nf-winsvc-createservicea)