Create or Modify System Process

T1543

Technique with 5 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence. When operating systems boot up, they can start processes that perform background system functions. On Windows and Linux, these system processes are referred to as services. On macOS, launchd processes known as Launch Daemon and Launch Agent are run to finish system initialization and load user specific parameters.

Adversaries may install new services, daemons, or agents that can be configured to execute at startup or a repeatable interval in order to establish persistence. Similarly, adversaries may modify existing services, daemons, or agents to achieve the same effect.

Services, daemons, or agents may be created with administrator privileges but executed under root/SYSTEM privileges. Adversaries may leverage this functionality to create or modify system processes in order to escalate privileges.

Detection rules89

Rules on DetectionCode tagged with T1543 or one of its sub-techniques.

Sigma51

RuleLevelLog sourceTechnique
CobaltStrike Service Installations - Systemcriticalwindows / NULLT1543.003
Moriya Rootkit - Systemcriticalwindows / NULLT1543.003
Allow Service Access Using Security Descriptor Tampering Via Sc.EXEhighwindows / process_creationT1543.003
CobaltStrike Service Installations - Securityhighwindows / NULLT1543.003
CodeIntegrity - Blocked Driver Load With Revoked Certificatehighwindows / NULLT1543
CodeIntegrity - Blocked Image/Driver Load For Policy Violationhighwindows / NULLT1543
Deny Service Access Using Security Descriptor Tampering Via Sc.EXEhighwindows / process_creationT1543.003
Devcon Execution Disabling VMware VMCI Devicehighwindows / process_creationT1543.003
Driver Load From A Temporary Directoryhighwindows / driver_loadT1543.003
KrbRelayUp Service Installationhighwindows / NULLT1543
Malicious Driver Loadhighwindows / driver_loadT1543.003
Potential CobaltStrike Service Installations - Registryhighwindows / registry_setT1543.003
Potential Persistence Via PlistBuddyhighmacos / process_creationT1543.001 T1543.004
ProcessHacker Privilege Elevationhighwindows / NULLT1543.003
PSEXEC Remote Execution File Artefacthighwindows / file_eventT1543.003

Splunk38

RuleTypeRiskData sourceTechnique
Cisco Isovalent - Late Process ExecutionAnomalyNULLCisco Isovalent Process ExecT1543
Cisco Isovalent - Nsenter Usage in Kubernetes PodAnomalyNULLCisco Isovalent Process ExecT1543
Cisco Isovalent - Shell ExecutionAnomalyNULLCisco Isovalent Process ExecT1543
Clop Ransomware Known Service NameTTPNULLWindows Event Log System 7045T1543
CMD Echo Pipe - EscalationTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1543.003
Impacket Lateral Movement Commandline ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1543.003
Impacket Lateral Movement smbexec CommandLine ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1543.003
Impacket Lateral Movement WMIExec Commandline ParametersTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1543.003
LLM Model File CreationHuntingNULLSysmon EventID 11T1543
MacOS Kextload UsageTTPNULLOsquery ResultsT1543
Possible Lateral Movement PowerShell SpawnAnomalyNULLSysmon EventID 1, CrowdStrike ProcessRollup2T1543.003
Randomly Generated Windows Service NameHuntingNULLWindows Event Log System 7045T1543.003
Sc exe Manipulating Windows ServicesTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1543.003
Services LOLBAS Execution Process SpawnTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1543.003
Suspicious Driver Loaded PathTTPNULLSysmon EventID 6T1543.003

Sub-techniques5

IDNameExamples
T1543.001Launch Agent23
T1543.002Systemd Service16
T1543.003Windows Service140
T1543.004Launch Daemon11
T1543.005Container Service0

Groups0

None recorded.

Software8

Campaigns0

None recorded.

Procedure examples8

Software8

Used byProcedure example
MalwareAkira _v2

Akira _v2 can create a child process for encryption.

MalwareBOLDMOVE

BOLDMOVE can free all resources and terminate itself on victim machines.

MalwareBRICKSTORM

BRICKSTORM has created a new background session and has spawned a child process of a parent process when it determines it is not running in its intended state.

MalwareCanisterWorm

CanisterWorm can establish persistence in CI/CD environments by launching a background process (deploy.js) with stolen tokens.

MalwareExaramel for Linux

Exaramel for Linux has a hardcoded location that it uses to achieve persistence if the startup system is Upstart or System V and it is running as root.

MalwareIMAPLoader

IMAPLoader modifies Windows tasks on the victim machine to reference a retrieved PE file through a path modification.

MalwareLITTLELAMB.WOOLTEA

LITTLELAMB.WOOLTEA can initialize itself as a daemon to run persistently in the background.

MalwareLunarMail

LunarMail can create an arbitrary process with a specified command line and redirect its output to a staging directory.

References3

  1. AppleDocs Launch Agent Daemons Open source
    Apple. (n.d.). Creating Launch Daemons and Agents. Retrieved July 10, 2017.
  2. OSX Malware Detection Open source
    Patrick Wardle. (2016, February 29). Let's Play Doctor: Practical OS X Malware Detection & Analysis. Retrieved November 17, 2024.
  3. TechNet Services Open source
    Microsoft. (n.d.). Services. Retrieved June 7, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.