Services Control Set
Data Type: services_control_set
Python Parser: RegServicesControlSet
Python Parser: RegServicesControlSet
Description
Each row is a Windows service or driver definition from a SYSTEM-hive control set, with service name, start mode, image path, account, dependencies, service DLL, failure actions, and registry provenance. Use it to identify persistence or privilege boundaries and correlate configured binaries. Configuration does not prove the service ran, and the relevant control set must be established.
Timeline
| Timeline Field | Data Field |
|---|---|
| Related User | key_security.owner_sid |
| Description | name |
display_name |
|
| Additional Description | service_type |
start_type |
|
image_path |
|
run_as |
Fields
| Output Name | Data Type | Description |
|---|---|---|
name |
String | unique identifier of the service (registry key name) |
service_type |
String | type of the service (e.g., Kernel driver, WIN32 service, packaged service) |
display_name |
String | human‑readable display name of the service |
description |
String | textual description of the service |
error_control |
String | error‑control setting (Ignore, Normal, Severe, Critical) |
service_type |
String | type of the service (duplicate entry for compatibility) |
start_type |
String | service start mode (Boot, System, Auto, Manual, Disabled) |
is_interactive |
Bool | whether the service is interactive |
is_packaged_service |
Bool | whether the service is a packaged (UWP) service |
is_service_driver |
Bool | whether the service is a driver (kernel, file‑system or recogniser) |
is_service_win32 |
Bool | whether the service is a WIN32 service |
image_path |
String | command line or executable path that the service runs |
group |
String | load‑order group name the service belongs to |
tag |
String | numeric tag used for service ordering |
depend_on_group |
String | service groups this service depends on |
depend_on_service |
String | other services this service depends on |
delete_flag |
String | flag indicating the service is marked for deletion |
object_name |
String | kernel object name for driver services |
run_as |
String | account name under which the service runs |
wow64 |
String | WOW64 flag indicating a 32‑bit service on a 64‑bit OS |
alias |
String | alternative name (alias) for the service |
delayed_auto_start |
String | whether the service uses delayed automatic start |
preshutdown_timeout |
String | pre‑shutdown timeout value (milliseconds) |
service_sid_type |
String | SID type assigned to the service (None, Unrestricted, Restricted) |
required_privileges |
String | list of privileges the service requires |
launch_protected |
String | protected‑process level of the service (None, Windows, Light, etc.) |
user_service_flags |
String | flags controlling user‑service permissions (e.g., DSMA allow) |
svchost_split_disable |
String | whether svchost split is disabled for this service |
package_fullname |
String | full package name for a packaged service |
app_usermodel_id |
String | AppUserModel ID associated with the service |
package_origin |
String | origin of the package (Unsigned, Inbox, Store, Developer) |
service_dll |
String | path to the ServiceDll implementing the service |
service_manifest |
String | path to the ServiceManifest file |
service_main |
String | name(s) of the service’s main entry point function(s) |
parameters_key_last_modif |
DateTime | last modification timestamp of the Parameters sub‑key |
parameters_service_dll |
String | ServiceDll value inside the Parameters sub‑key |
parameters_service_manifest |
String | ServiceManifest value inside the Parameters sub‑key |
parameters_service_main |
String | ServiceMain value inside the Parameters sub‑key |
performance_key_last_modif |
DateTime | last modification timestamp of the Performance sub‑key |
performance_library |
String | library file used for performance counters |
performance_open_function |
String | function name that opens performance data |
performance_collect_function |
String | function name that collects performance data |
performance_close_function |
String | function name that closes performance data |
failure_actions |
String | binary blob describing service failure actions |
failure_command |
String | command executed when the service fails |
failure_actions_on_non_crash_failures |
Bool | whether failure actions apply to non‑crash failures |
key_path |
String | full registry key name |
key_modif_time |
DateTime | last modification timestamp of the registry key |
key_security |
Object | |
key_security.owner_sid |
String | SID of the user that owns the registry key |
key_security.group_sid |
String | SID of the group that owns the registry key |
key_security.control_flags[] |
Array[String] | security descriptor control flags for the key |
key_security.sacl_aces[] |
Array[Object] | |
key_security.sacl_aces[].ace_type |
String | type of ACE (e.g., allow, deny) |
key_security.sacl_aces[].ace_flags[] |
Array[String] | ACE flags that modify inheritance or behavior |
key_security.sacl_aces[].rights[] |
Array[String] | permissions granted or denied by the ACE |
key_security.sacl_aces[].account_sid |
String | SID of the account the ACE applies to |
key_security.sacl_aces[].ace_size |
Int | declared ACE size in bytes |
key_security.sacl_aces[].object_type_guid |
String | GUID identifying the object type governed by the ACE |
key_security.sacl_aces[].inherited_object_type_guid |
String | GUID identifying the inherited object type governed by the ACE |
key_security.sacl_aces[].raw_hex |
String | raw ACE bytes preserved as hexadecimal |
key_security.dacl_aces[] |
Array[Object] | |
key_security.dacl_aces[].ace_type |
String | type of ACE (e.g., allow, deny) |
key_security.dacl_aces[].ace_flags[] |
Array[String] | ACE flags that modify inheritance or behavior |
key_security.dacl_aces[].rights[] |
Array[String] | permissions granted or denied by the ACE |
key_security.dacl_aces[].account_sid |
String | SID of the account the ACE applies to |
key_security.dacl_aces[].ace_size |
Int | declared ACE size in bytes |
key_security.dacl_aces[].object_type_guid |
String | GUID identifying the object type governed by the ACE |
key_security.dacl_aces[].inherited_object_type_guid |
String | GUID identifying the inherited object type governed by the ACE |
key_security.dacl_aces[].raw_hex |
String | raw ACE bytes preserved as hexadecimal |