logo

New RecoverIt Tool Abuses Windows Service Failure Recovery to Execute Malicious Payloads

ID: e6b1db07-d973-58b5-88dc-660c096babb1

STIX ID: report--e6b1db07-d973-58b5-88dc-660c096babb1

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-02-09

Date Updated: 2026-05-22

Author: Divya

...
...

RecoverIt is an offensive tool that enables stealthy lateral movement and persistence by modifying Windows service failure recovery actions (FailureCommand/FailureActions) to execute payloads when a service crashes, while leaving the legitimate ImagePath unchanged; this bypasses common EDR and service-creation detection that focus on ImagePath changes. The report details the attack flow (identify crash-prone service, modify recovery actions, trigger crash), shows artifacts to monitor (registry FailureCommand/FailureActions, Event IDs 7024/7031 and services.exe execution), and recommends expanding monitoring to include service recovery settings and associated event-log correlations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.