T1007 System Service Discovery — ATT&CK Technique
Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as sc query, tasklist /svc, systemctl --type=service, and net start. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS. Adversaries may use the information from System Service Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Detection coverage (13)
- Potential Registry Reconnaissance Via PowerShell Script medium
- Net.EXE Execution low
- SC.EXE Query Execution low
- Crontab Enumeration low
- ESXi System Information Discovery Via ESXCLI medium
- ESXi VM List Discovery Via ESXCLI medium
- ESXi Network Configuration Discovery Via ESXCLI medium
- ESXi VSAN Information Discovery Via ESXCLI medium
- Potential Configuration And Service Reconnaissance Via Reg.EXE medium
- ESXi Storage Information Discovery Via ESXCLI medium
- HackTool - PCHunter Execution high
- Windows Net System Service Discovery
- Windows WinPEAS PowerShell Script Execution
Malware using this technique
- Sykipot
- Qilin
- Comnie
- SysUpdate
- Net
- Elise
- PoshC2
- SLOTHFULMEDIA
- Medusa Ransomware
- Kwampirs
- Tasklist
- jRAT
- HotCroissant
- RATANKBA
- BBSRAT
- RainyDay
- Cobalt Strike
- Volgmer
- LookBack
- Heyoka Backdoor
- Caterpillar WebShell
- InvisiMole
- GreyEnergy
- SUNBURST
- HyperBro
- Black Basta
- Embargo
- Hydraq
- GravityRAT
- REvil
- Cuba
- SynAck
- Sardonic
- S-Type
- GeminiDuke
- ZLib
- DarkTortilla
- Emissary
- Babuk
- Ixeshe
- SombRAT
- WINERACK
- Epic
- BitPaymer
- TrickBot
- PUBLOAD
- LAMEHUG
- Ursnif
- JPIN
- Dyre