Bidda Sovereign Intelligence · 10,085 Verified Nodes · 39 Sovereign Pillars

MITRE ATT&CK T1543.003: Windows Service (Sub-Technique of T1543 - Persistence + Privilege Escalation)

MITRE ATT&CK T1543.003 covers adversary persistence via Windows Service creation or modification (Service Control Manager). Lateral movement frameworks…

What MITRE ATT&CK T1543.003: Windows Service (Sub-Technique of T1543 - Persistence + Privilege Escalation) requires

MITRE ATT&CK T1543.003 covers adversary persistence via Windows Service creation or modification (Service Control Manager). Lateral movement frameworks (PsExec, Impacket-smbexec, Cobalt Strike) and most ransomware operators create services for elevated execution and persistence. Compliance obligations include NIST SP 800-53 SI-7, AU-12 (Event ID 4697, 7045), CM-7, ISO 27001 A.8.32, A.8.16, PCI DSS Req 5.2 and Req 10.4.

Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:

Primary source: https://attack.mitre.org/techniques/T1543/003/

SHA-256 integrity: 7e135aec1348b37500ea075ba014358e5e6b58f3cf15d7da19f13b64f94766f9

Primary Citations — 7 traced to source

  • MITRE ATT&CK Technique T1543.003: Windows Service (https://attack.mitre.org/techniques/T1543/003/)
  • NIST SP 800-53 Rev 5: SI-7, CM-7, AU-2, AU-12

+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.

Access

⚠ Important: Human Verification Required

Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.