Weak Service Permissions
MITRE ATT&CK™ Hijack Execution Flow - Technique T1574
Theory
Practice
AccessChk
#list all the services that a specific user can modify.
accesschk64.exe -uwcqv "pwned" * -accepteula
accesschk64.exe -uwcqv "Authenticated Users" * -accepteula
accesschk64.exe -uwcqv "BUILTIN\Users" * -accepteula
accesschk.exe -uwcqv %USERNAME% * -accepteula
#list permissions for "VulnSvc" service.
accesschk64.exe -uwcqv VulnSvc -accepteulaPowerUp
. .\PowerUp.ps1
Get-ModifiableServicewinPEAS
winPEASx64.exe servicesinfoResources
Last updated