Weak Service Permissions
MITRE ATT&CK™ Hijack Execution Flow - Technique T1574
Last updated
Was this helpful?
MITRE ATT&CK™ Hijack Execution Flow - Technique T1574
Last updated
Was this helpful?
It is very often in Windows environments to discover services that run with SYSTEM privileges. If you have permissions over the service you can use it to escalate you privileges.
If we have enough permissions over a service, we can edit the binPath
parameters and replace it with our own binary or command.