Skip to content

Services Control Set

Data Type: services_control_set
Python Parser: RegServicesControlSet

Description

Each row is a Windows service or driver definition from a SYSTEM-hive control set, with service name, start mode, image path, account, dependencies, service DLL, failure actions, and registry provenance. Use it to identify persistence or privilege boundaries and correlate configured binaries. Configuration does not prove the service ran, and the relevant control set must be established.

Timeline

Timeline Field Data Field
Related User key_security.owner_sid
Description name
display_name
Additional Description service_type
start_type
image_path
run_as

Fields

Output Name Data Type Description
name String unique identifier of the service (registry key name)
service_type String type of the service (e.g., Kernel driver, WIN32 service, packaged service)
display_name String human‑readable display name of the service
description String textual description of the service
error_control String error‑control setting (Ignore, Normal, Severe, Critical)
service_type String type of the service (duplicate entry for compatibility)
start_type String service start mode (Boot, System, Auto, Manual, Disabled)
is_interactive Bool whether the service is interactive
is_packaged_service Bool whether the service is a packaged (UWP) service
is_service_driver Bool whether the service is a driver (kernel, file‑system or recogniser)
is_service_win32 Bool whether the service is a WIN32 service
image_path String command line or executable path that the service runs
group String load‑order group name the service belongs to
tag String numeric tag used for service ordering
depend_on_group String service groups this service depends on
depend_on_service String other services this service depends on
delete_flag String flag indicating the service is marked for deletion
object_name String kernel object name for driver services
run_as String account name under which the service runs
wow64 String WOW64 flag indicating a 32‑bit service on a 64‑bit OS
alias String alternative name (alias) for the service
delayed_auto_start String whether the service uses delayed automatic start
preshutdown_timeout String pre‑shutdown timeout value (milliseconds)
service_sid_type String SID type assigned to the service (None, Unrestricted, Restricted)
required_privileges String list of privileges the service requires
launch_protected String protected‑process level of the service (None, Windows, Light, etc.)
user_service_flags String flags controlling user‑service permissions (e.g., DSMA allow)
svchost_split_disable String whether svchost split is disabled for this service
package_fullname String full package name for a packaged service
app_usermodel_id String AppUserModel ID associated with the service
package_origin String origin of the package (Unsigned, Inbox, Store, Developer)
service_dll String path to the ServiceDll implementing the service
service_manifest String path to the ServiceManifest file
service_main String name(s) of the service’s main entry point function(s)
parameters_key_last_modif DateTime last modification timestamp of the Parameters sub‑key
parameters_service_dll String ServiceDll value inside the Parameters sub‑key
parameters_service_manifest String ServiceManifest value inside the Parameters sub‑key
parameters_service_main String ServiceMain value inside the Parameters sub‑key
performance_key_last_modif DateTime last modification timestamp of the Performance sub‑key
performance_library String library file used for performance counters
performance_open_function String function name that opens performance data
performance_collect_function String function name that collects performance data
performance_close_function String function name that closes performance data
failure_actions String binary blob describing service failure actions
failure_command String command executed when the service fails
failure_actions_on_non_crash_failures Bool whether failure actions apply to non‑crash failures
key_path String full registry key name
key_modif_time DateTime last modification timestamp of the registry key
key_security Object
key_security.owner_sid String SID of the user that owns the registry key
key_security.group_sid String SID of the group that owns the registry key
key_security.control_flags[] Array[String] security descriptor control flags for the key
key_security.sacl_aces[] Array[Object]
key_security.sacl_aces[].ace_type String type of ACE (e.g., allow, deny)
key_security.sacl_aces[].ace_flags[] Array[String] ACE flags that modify inheritance or behavior
key_security.sacl_aces[].rights[] Array[String] permissions granted or denied by the ACE
key_security.sacl_aces[].account_sid String SID of the account the ACE applies to
key_security.sacl_aces[].ace_size Int declared ACE size in bytes
key_security.sacl_aces[].object_type_guid String GUID identifying the object type governed by the ACE
key_security.sacl_aces[].inherited_object_type_guid String GUID identifying the inherited object type governed by the ACE
key_security.sacl_aces[].raw_hex String raw ACE bytes preserved as hexadecimal
key_security.dacl_aces[] Array[Object]
key_security.dacl_aces[].ace_type String type of ACE (e.g., allow, deny)
key_security.dacl_aces[].ace_flags[] Array[String] ACE flags that modify inheritance or behavior
key_security.dacl_aces[].rights[] Array[String] permissions granted or denied by the ACE
key_security.dacl_aces[].account_sid String SID of the account the ACE applies to
key_security.dacl_aces[].ace_size Int declared ACE size in bytes
key_security.dacl_aces[].object_type_guid String GUID identifying the object type governed by the ACE
key_security.dacl_aces[].inherited_object_type_guid String GUID identifying the inherited object type governed by the ACE
key_security.dacl_aces[].raw_hex String raw ACE bytes preserved as hexadecimal