โ† All cheat sheets

SC

Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.

Windows Service Control Manager (sc.exe).
Create, modify, start, stop, and delete Windows services.

QUERY SERVICES#


    

LIST SERVICES#

sc query                             # Running services
sc query state= all                  # All services
sc query type= service               # Win32 services only
sc query type= driver                # Drivers only
sc query state= inactive             # Stopped services

# Note: space after = is required!

sc queryex                           # Extended query (PIDs)
sc queryex type= service state= all

QUERY SPECIFIC SERVICE#

sc query ServiceName                 # Basic status
sc queryex ServiceName               # Extended (PID, flags)
sc qc ServiceName                    # Configuration
sc qdescription ServiceName          # Description
sc qfailure ServiceName              # Failure actions
sc qsidtype ServiceName              # SID type
sc qprivs ServiceName                # Required privileges

SERVICE STATES#

# STATE values from sc query:
# 1 - STOPPED
# 2 - START_PENDING
# 3 - STOP_PENDING
# 4 - RUNNING
# 5 - CONTINUE_PENDING
# 6 - PAUSE_PENDING
# 7 - PAUSED

CONTROL SERVICES#

sc start ServiceName                 # Start service
sc stop ServiceName                  # Stop service
sc pause ServiceName                 # Pause service
sc continue ServiceName              # Resume paused
sc interrogate ServiceName           # Update status

# Control codes
sc control ServiceName 129           # Custom control code

CREATE SERVICE#

sc create ServiceName binPath= "C:\path\to\service.exe"

# Full syntax
sc create ServiceName ^
    type= own ^
    start= auto ^
    binPath= "C:\path\service.exe" ^
    DisplayName= "My Service" ^
    depend= ServiceDependency ^
    obj= LocalSystem ^
    password= password

# Service types
type= own                            # Own process
type= share                          # Shared process
type= kernel                         # Kernel driver
type= filesys                        # File system driver
type= interact                       # Interactive (deprecated)

# Start types
start= boot                          # Boot-start driver
start= system                        # System-start driver
start= auto                          # Auto-start
start= demand                        # Manual start
start= disabled                      # Disabled
start= delayed-auto                  # Delayed auto-start

# Service accounts
obj= LocalSystem                     # SYSTEM account
obj= "NT AUTHORITY\LocalService"     # Local Service
obj= "NT AUTHORITY\NetworkService"   # Network Service
obj= "DOMAIN\User"                   # Domain user

MODIFY SERVICE#

sc config ServiceName start= auto    # Change start type
sc config ServiceName start= demand  # Set to manual
sc config ServiceName start= disabled
sc config ServiceName binPath= "new\path.exe"
sc config ServiceName DisplayName= "New Name"
sc config ServiceName obj= "DOMAIN\User" password= "pass"
sc config ServiceName depend= Dependency1/Dependency2

# Clear dependencies
sc config ServiceName depend= ""

DELETE SERVICE#

sc delete ServiceName                # Delete service

# Service must be stopped first
sc stop ServiceName
sc delete ServiceName

FAILURE ACTIONS#

sc failure ServiceName reset= 86400 actions= restart/60000
sc failure ServiceName actions= restart/60000/restart/120000/run/180000
sc failure ServiceName command= "C:\path\recovery.exe"

# Actions format: action/delay (milliseconds)
# Actions: restart, run, reboot, ""

# Reset period in seconds (0 = never reset failure count)
sc failure ServiceName reset= 0 actions= restart/60000

# View failure settings
sc qfailure ServiceName

DESCRIPTION#

sc description ServiceName "Service description text"
sc qdescription ServiceName          # View description

SECURITY#

sc sdshow ServiceName                # Show security descriptor
sc sdset ServiceName SDDL_STRING     # Set security descriptor

# SDDL format example:
# D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)

SID TYPE#

sc sidtype ServiceName none          # No SID
sc sidtype ServiceName unrestricted  # Unrestricted SID
sc sidtype ServiceName restricted    # Restricted SID

PRIVILEGES#

sc privs ServiceName SeDebugPrivilege/SeTcbPrivilege
sc qprivs ServiceName                # Query privileges

REMOTE SERVICES#

sc \\COMPUTER query                  # Query remote
sc \\COMPUTER start ServiceName      # Start remote
sc \\COMPUTER stop ServiceName       # Stop remote
sc \\COMPUTER create ServiceName binPath= "path"
sc \\COMPUTER delete ServiceName

ENUMERATION#

sc enumdepend ServiceName            # Dependencies
sc GetDisplayName ServiceName        # Get display name
sc GetKeyName "Display Name"         # Get service name

DRIVER SERVICES#

sc query type= driver                # List drivers
sc query type= driver state= all

# Create kernel driver
sc create DriverName type= kernel binPath= "C:\path\driver.sys"

BOOT CONFIG#

sc boot ok                           # Mark last boot good
sc boot bad                          # Mark last boot bad

USEFUL QUERIES#

# Find services running as SYSTEM
sc query state= all | findstr /i "SERVICE_NAME"
for /f "tokens=2" %s in ('sc query state^= all ^| findstr SERVICE_NAME') do @sc qc %s | findstr /i "BINARY_PATH_NAME SERVICE_START_NAME"

# Find services with unquoted paths (vulnerability)
wmic service get name,pathname | findstr /i /v "C:\Windows\\" | findstr /i /v """

# Find services with weak permissions
sc sdshow ServiceName

# Check for writable service binaries
icacls "C:\path\to\service.exe"

SECURITY ANALYSIS#

# List all services and their paths
sc query state= all | findstr SERVICE_NAME > services.txt
for /f "tokens=2" %s in (services.txt) do @sc qc %s

# Find services not in System32
for /f "tokens=2" %s in ('sc query state^= all ^| findstr SERVICE_NAME') do @sc qc %s | findstr /v "system32" | findstr /i "BINARY_PATH_NAME"

# Check service permissions
sc sdshow ServiceName

# Common vulnerable services
# - Unquoted service paths
# - Weak binary permissions
# - Writable service directories

PRIVILEGE ESCALATION#

# Check for modifiable services (use accesschk from Sysinternals)
accesschk.exe -uwcqv "Authenticated Users" *
accesschk.exe -uwcqv "Users" *
accesschk.exe -uwcqv "Everyone" *

# Check service binary permissions
icacls "C:\path\to\service.exe"

# Look for unquoted paths with spaces
wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """

COMMON SERVICES#

# Important Windows services
wuauserv                             # Windows Update
bits                                 # Background Intelligent Transfer
WinDefend                            # Windows Defender
mpssvc                               # Windows Firewall
W32Time                              # Windows Time
Dnscache                             # DNS Client
LanmanServer                         # Server (SMB)
LanmanWorkstation                    # Workstation
RemoteRegistry                       # Remote Registry
TermService                          # Remote Desktop
WinRM                                # Windows Remote Management
Spooler                              # Print Spooler

QUICK REFERENCE#

sc query ServiceName                 # Query status
sc qc ServiceName                    # Query config
sc start ServiceName                 # Start
sc stop ServiceName                  # Stop
sc config ServiceName start= auto    # Set auto-start
sc config ServiceName start= disabled
sc delete ServiceName                # Delete (must be stopped)

# Create service
sc create Name binPath= "path" start= auto DisplayName= "Name"

# Remote
sc \\COMPUTER query ServiceName

# Failure recovery
sc failure Name actions= restart/60000 reset= 86400