scmexec.md (2155B)
1 --- 2 title: "SCMExec" 3 section: "Windows" 4 sectionSlug: "windows-hardening" 5 sourcePath: "src/windows-hardening/lateral-movement/scmexec.md" 6 sourceUrl: "https://github.com/HackTricks-wiki/hacktricks/blob/188de82beb54e70956b2952367a0af91d26758b8/src/windows-hardening/lateral-movement/scmexec.md" 7 sha: "188de82beb54e70956b2952367a0af91d26758b8" 8 isIndex: false 9 modified: true 10 license: "CC-BY-NC-4.0" 11 --- 12 13 # SCMExec 14 15 ## How It Works 16 17 The Service Control Manager Remote Protocol (SCMR) is an RPC-based protocol for configuring and controlling Windows services on a remote computer. With sufficient permissions, an operator can create or reconfigure a service whose binary path contains a command and then start that service to execute the command remotely.<sup>[[1]](#references)</sup> 18 19 If no service account is specified, `CreateService` uses `LocalSystem`, which has extensive local privileges. This explains the high impact of successful SCM execution. It does not inherently disable UAC or Microsoft Defender: the caller still needs remote SCM rights, and endpoint controls can inspect or block the service or payload.<sup>[[3]](#references)</sup><sup>[[4]](#references)</sup> 20 21 ## Tools 22 23 **SharpMove** supports authenticated remote execution through SCM and several other Windows mechanisms. The following example selects its SCM action, creates a service named `WindowsDebug`, and points it at a payload already present on the remote host.<sup>[[2]](#references)</sup> 24 25 ```powershell 26 SharpMove.exe action=scm computername=remote.host.local command="C:\windows\temp\payload.exe" servicename=WindowsDebug amsi=true 27 ``` 28 29 ## References 30 31 - [1] [Microsoft Open Specifications - Service Control Manager Remote Protocol overview](https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-scmr/d5bd5712-fa64-44bf-9433-3651f6a5ce97) 32 - [2] [GitHub - SharpMove](https://github.com/0xthirteen/SharpMove) 33 - [3] [Microsoft Learn - LocalSystem account](https://learn.microsoft.com/en-us/windows/win32/services/localsystem-account) 34 - [4] [Microsoft Learn - `CreateService` function](https://learn.microsoft.com/en-us/windows/win32/api/winsvc/nf-winsvc-createservicea)