New RecoverIt Tool Abuses Windows Service Failure Recovery to Execute Malicious Payloads
ID: e6b1db07-d973-58b5-88dc-660c096babb1
STIX ID: report--e6b1db07-d973-58b5-88dc-660c096babb1
Feed Name: GBHackers
RecoverIt is an offensive tool that enables stealthy lateral movement and persistence by modifying Windows service failure recovery actions (FailureCommand/FailureActions) to execute payloads when a service crashes, while leaving the legitimate ImagePath unchanged; this bypasses common EDR and service-creation detection that focus on ImagePath changes. The report details the attack flow (identify crash-prone service, modify recovery actions, trigger crash), shows artifacts to monitor (registry FailureCommand/FailureActions, Event IDs 7024/7031 and services.exe execution), and recommends expanding monitoring to include service recovery settings and associated event-log correlations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
