CAPEC-550: Install New Service |
Description When an operating system starts, it also starts programs called services or daemons. Adversaries may install a new service which will be executed at startup (on a Windows system, by modifying the registry). The service name may be disguised by using a name from a related operating system or benign software. Services are usually run with elevated privileges. Mitigations
| Limit privileges of user accounts so new service creation can only be performed by authorized administrators. |
Taxonomy Mappings CAPEC mappings to ATT&CK techniques leverage an inheritance model to streamline and minimize direct CAPEC/ATT&CK mappings. Inheritance of a mapping is indicated by text stating that the parent CAPEC has relevant ATT&CK mappings. Note that the ATT&CK Enterprise Framework does not use an inheritance model as part of the mapping to CAPEC.Relevant to the ATT&CK taxonomy mapping (also see parent) | Entry ID | Entry Name |
|---|
| 1543 | Create or Modify System Process |
Content History | Submissions |
|---|
| Submission Date | Submitter | Organization |
|---|
| 2015-11-09 (Version 2.7) | CAPEC Content Team | The MITRE Corporation | | | Modifications |
|---|
| Modification Date | Modifier | Organization |
|---|
| 2017-05-01 (Version 2.10) | CAPEC Content Team | The MITRE Corporation | | Updated References | | 2018-07-31 (Version 2.12) | CAPEC Content Team | The MITRE Corporation | | Updated References | | 2019-04-04 (Version 3.1) | CAPEC Content Team | The MITRE Corporation | | Updated Related_Weaknesses | | 2020-07-30 (Version 3.3) | CAPEC Content Team | The MITRE Corporation | | Updated Taxonomy_Mappings | | 2021-06-24 (Version 3.5) | CAPEC Content Team | The MITRE Corporation | | Updated Taxonomy_Mappings | | 2022-09-29 (Version 3.8) | CAPEC Content Team | The MITRE Corporation | | Updated Taxonomy_Mappings |
More information is available — Please select a different filter.
|