SC
Authorized use only. Offensive reference for systems you own or are explicitly permitted to test. You are responsible for staying within the law.
Windows Service Control Manager (sc.exe). Create, modify, start, stop, and delete Windows services.
QUERY SERVICES#
LIST SERVICES#
sc query # Running services sc query state= all # All services sc query type= service # Win32 services only sc query type= driver # Drivers only sc query state= inactive # Stopped services # Note: space after = is required! sc queryex # Extended query (PIDs) sc queryex type= service state= all
QUERY SPECIFIC SERVICE#
sc query ServiceName # Basic status sc queryex ServiceName # Extended (PID, flags) sc qc ServiceName # Configuration sc qdescription ServiceName # Description sc qfailure ServiceName # Failure actions sc qsidtype ServiceName # SID type sc qprivs ServiceName # Required privileges
SERVICE STATES#
# STATE values from sc query: # 1 - STOPPED # 2 - START_PENDING # 3 - STOP_PENDING # 4 - RUNNING # 5 - CONTINUE_PENDING # 6 - PAUSE_PENDING # 7 - PAUSED
CONTROL SERVICES#
sc start ServiceName # Start service sc stop ServiceName # Stop service sc pause ServiceName # Pause service sc continue ServiceName # Resume paused sc interrogate ServiceName # Update status # Control codes sc control ServiceName 129 # Custom control code
CREATE SERVICE#
sc create ServiceName binPath= "C:\path\to\service.exe"
# Full syntax
sc create ServiceName ^
type= own ^
start= auto ^
binPath= "C:\path\service.exe" ^
DisplayName= "My Service" ^
depend= ServiceDependency ^
obj= LocalSystem ^
password= password
# Service types
type= own # Own process
type= share # Shared process
type= kernel # Kernel driver
type= filesys # File system driver
type= interact # Interactive (deprecated)
# Start types
start= boot # Boot-start driver
start= system # System-start driver
start= auto # Auto-start
start= demand # Manual start
start= disabled # Disabled
start= delayed-auto # Delayed auto-start
# Service accounts
obj= LocalSystem # SYSTEM account
obj= "NT AUTHORITY\LocalService" # Local Service
obj= "NT AUTHORITY\NetworkService" # Network Service
obj= "DOMAIN\User" # Domain user
MODIFY SERVICE#
sc config ServiceName start= auto # Change start type sc config ServiceName start= demand # Set to manual sc config ServiceName start= disabled sc config ServiceName binPath= "new\path.exe" sc config ServiceName DisplayName= "New Name" sc config ServiceName obj= "DOMAIN\User" password= "pass" sc config ServiceName depend= Dependency1/Dependency2 # Clear dependencies sc config ServiceName depend= ""
DELETE SERVICE#
sc delete ServiceName # Delete service # Service must be stopped first sc stop ServiceName sc delete ServiceName
FAILURE ACTIONS#
sc failure ServiceName reset= 86400 actions= restart/60000 sc failure ServiceName actions= restart/60000/restart/120000/run/180000 sc failure ServiceName command= "C:\path\recovery.exe" # Actions format: action/delay (milliseconds) # Actions: restart, run, reboot, "" # Reset period in seconds (0 = never reset failure count) sc failure ServiceName reset= 0 actions= restart/60000 # View failure settings sc qfailure ServiceName
DESCRIPTION#
sc description ServiceName "Service description text" sc qdescription ServiceName # View description
SECURITY#
sc sdshow ServiceName # Show security descriptor sc sdset ServiceName SDDL_STRING # Set security descriptor # SDDL format example: # D:(A;;CCLCSWRPWPDTLOCRRC;;;SY)(A;;CCDCLCSWRPWPDTLOCRSDRCWDWO;;;BA)
SID TYPE#
sc sidtype ServiceName none # No SID sc sidtype ServiceName unrestricted # Unrestricted SID sc sidtype ServiceName restricted # Restricted SID
PRIVILEGES#
sc privs ServiceName SeDebugPrivilege/SeTcbPrivilege sc qprivs ServiceName # Query privileges
REMOTE SERVICES#
sc \\COMPUTER query # Query remote sc \\COMPUTER start ServiceName # Start remote sc \\COMPUTER stop ServiceName # Stop remote sc \\COMPUTER create ServiceName binPath= "path" sc \\COMPUTER delete ServiceName
ENUMERATION#
sc enumdepend ServiceName # Dependencies sc GetDisplayName ServiceName # Get display name sc GetKeyName "Display Name" # Get service name
DRIVER SERVICES#
sc query type= driver # List drivers sc query type= driver state= all # Create kernel driver sc create DriverName type= kernel binPath= "C:\path\driver.sys"
BOOT CONFIG#
sc boot ok # Mark last boot good sc boot bad # Mark last boot bad
USEFUL QUERIES#
# Find services running as SYSTEM
sc query state= all | findstr /i "SERVICE_NAME"
for /f "tokens=2" %s in ('sc query state^= all ^| findstr SERVICE_NAME') do @sc qc %s | findstr /i "BINARY_PATH_NAME SERVICE_START_NAME"
# Find services with unquoted paths (vulnerability)
wmic service get name,pathname | findstr /i /v "C:\Windows\\" | findstr /i /v """
# Find services with weak permissions
sc sdshow ServiceName
# Check for writable service binaries
icacls "C:\path\to\service.exe"
SECURITY ANALYSIS#
# List all services and their paths
sc query state= all | findstr SERVICE_NAME > services.txt
for /f "tokens=2" %s in (services.txt) do @sc qc %s
# Find services not in System32
for /f "tokens=2" %s in ('sc query state^= all ^| findstr SERVICE_NAME') do @sc qc %s | findstr /v "system32" | findstr /i "BINARY_PATH_NAME"
# Check service permissions
sc sdshow ServiceName
# Common vulnerable services
# - Unquoted service paths
# - Weak binary permissions
# - Writable service directories
PRIVILEGE ESCALATION#
# Check for modifiable services (use accesschk from Sysinternals) accesschk.exe -uwcqv "Authenticated Users" * accesschk.exe -uwcqv "Users" * accesschk.exe -uwcqv "Everyone" * # Check service binary permissions icacls "C:\path\to\service.exe" # Look for unquoted paths with spaces wmic service get name,displayname,pathname,startmode | findstr /i "auto" | findstr /i /v "C:\Windows\\" | findstr /i /v """
COMMON SERVICES#
# Important Windows services wuauserv # Windows Update bits # Background Intelligent Transfer WinDefend # Windows Defender mpssvc # Windows Firewall W32Time # Windows Time Dnscache # DNS Client LanmanServer # Server (SMB) LanmanWorkstation # Workstation RemoteRegistry # Remote Registry TermService # Remote Desktop WinRM # Windows Remote Management Spooler # Print Spooler
QUICK REFERENCE#
sc query ServiceName # Query status sc qc ServiceName # Query config sc start ServiceName # Start sc stop ServiceName # Stop sc config ServiceName start= auto # Set auto-start sc config ServiceName start= disabled sc delete ServiceName # Delete (must be stopped) # Create service sc create Name binPath= "path" start= auto DisplayName= "Name" # Remote sc \\COMPUTER query ServiceName # Failure recovery sc failure Name actions= restart/60000 reset= 86400