TACTIC: EXECUTION

Service Execution (T1569.002): real cases

MITRE Definition ↗
Adversaries create and run Windows services to execute payloads with system privileges.

Key Facts

Technique ID
T1569.002
Execution
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1569.002.
  • Tactical Phase: Execution.
  • Substantiated in 1 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Indictment ¶ 15, Page 8
"Vasinskyi used Kaseya VSA management agents to execute arbitrary PowerShell commands disguised as automated administrative service tasks."
U.S. District Court for the Northern District of Texas View full case dossier →