Processes & Services
MITRE ATT&CK™ Process Discovery & System Service Discovery - Technique T1057 & T1007
Theory
Practice
Services
#Net command
net start
#WMI
wmic service list brief
wmic service get name,displayname,pathname,startmode
#sc.exe
sc.exe query state= all# WMI
## Basic Usage
Get-CimInstance -ClassName win32_service | Select Name,State,PathName
## Running Services
Get-CimInstance -ClassName win32_service | Select Name,State,PathName | Where-Object {$_.State -like 'Running'}
# WMI Wrapper
## Basic Usage
Get-Service
## Running Services
Get-Service | Where-Object {$_.Status -eq "Running"}Processes
Resources
Last updated