There's More than One Way to Trigger a Windows Service
ID: 1f1e221f-e318-5663-9061-a63af6d3ecca
STIX ID: report--1f1e221f-e318-5663-9061-a63af6d3ecca
Feed Name: TrustedSec blog
This blog post examines Windows service triggers: what they are, how to enumerate them (sc.exe, QueryServiceConfig2/Win32 API, MS-SCMR/RPC and registry), the existing trigger types (device arrival, domain join, firewall, group policy, IP address available, network endpoint/named pipe and RPC, WNF, ETW and an undocumented Aggregate type), and practical ways to activate each trigger. The author highlights that several triggers allow low-privilege users to start services they normally could not (examples: RemoteRegistry via named pipe, ClipSVC via RPC endpoint, WebClient via ETW), provides command and code-oriented examples, discusses pitfalls (e.g., firewall trigger misbehavior), and frames these behaviors as useful for pentesting and further research.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
