What MITRE ATT&CK T1543.003: Windows Service (Sub-Technique of T1543 - Persistence + Privilege Escalation) requires
MITRE ATT&CK T1543.003 covers adversary persistence via Windows Service creation or modification (Service Control Manager). Lateral movement frameworks (PsExec, Impacket-smbexec, Cobalt Strike) and most ransomware operators create services for elevated execution and persistence. Compliance obligations include NIST SP 800-53 SI-7, AU-12 (Event ID 4697, 7045), CM-7, ISO 27001 A.8.32, A.8.16, PCI DSS Req 5.2 and Req 10.4.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1543/003/
SHA-256 integrity: 7e135aec1348b37500ea075ba014358e5e6b58f3cf15d7da19f13b64f94766f9
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1543.003: Windows Service (https://attack.mitre.org/techniques/T1543/003/)
- NIST SP 800-53 Rev 5: SI-7, CM-7, AU-2, AU-12
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1543-003-windows-service.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1543-003-windows-service.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1543-003-windows-service
- Back to registry: Browse all 10,085 compliance nodes