T1489 Service Stop — ATT&CK Technique
Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment. Adversaries may accomplish this by disabling individual services of high importance to an organization, such as MSExchangeIS, which will make Exchange content inaccessible. In some cases, adversaries may stop or disable many or all services to render systems unusable. Services or processes may not allow for modification of their data stores while running. Adversaries may stop services or processes in order to conduct Data Destruction or Data Encrypted for Impact on the data stores of services like Exchange and SQL Server, or on virtual machines hosted on ESXi infrastructure. Threat actors may also disable or stop service in cloud environments. For example, by leveraging the `DisableAPIServiceAccess` API in AWS, a threat actor may prevent the service from creating service-linked roles on new accounts in the AWS Organization.
Detection coverage (37)
- Disable Or Stop Services medium
- Process Terminated Via Taskkill low
- Azure Container Registry Created or Deleted low
- Azure Kubernetes Network Policy Change medium
- Azure Kubernetes Service Account Modified or Deleted medium
- Azure Kubernetes Cluster Created or Deleted low
- Azure Kubernetes Sensitive Role Access medium
- Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted medium
- Azure Kubernetes Secret or Config Object Access medium
- Stop Windows Service Via PowerShell Stop-Service low
- Potential Abuse of Linux Magic System Request Key medium
- Application Uninstalled low
- Important Scheduled Task Deleted or Disabled high
- Stop Windows Service Via Net.EXE low
- Delete Important Scheduled Task high
- Disable Important Scheduled Task high
- Stop Windows Service Via Sc.EXE low
- Delete All Scheduled Tasks high
- Suspicious Windows Service Tampering high
- Azure Application Deleted medium
- Ollama Abnormal Service Crash Availability Attack
- Excessive Attempt To Disable Services
- Linux Auditd Auditd Service Stop
- Linux Auditd Osquery Service Stop
- Linux Auditd Stop Services
- Linux Auditd Sysmon Service Stop
- Linux Disable Services
- Linux Magic SysRq Key Abuse
- Linux Stop Services
- Windows Excessive Service Stop Attempt
- Windows Processes Killed By Industroyer2 Malware
- Windows Security Account Manager Stopped
- Windows Service Deletion In Registry
- Windows Service Stop Win Updates
- Windows Service Stop Attempt
- Windows Set Account Password Policy To Unlimited Via Net
- Windows Service Stop By Deletion
Malware using this technique
- Clop
- LookBack
- Embargo
- Meteor
- Hannotog
- WannaCry
- PHASEJAM
- Royal
- Diavol
- Avaddon
- Olympic Destroyer
- Cheerscrypt
- Prestige
- Pay2Key
- Babuk
- BlackCat
- Qilin
- RobbinHood
- LockBit 2.0
- Megazord
- REvil
- Conti
- Ryuk
- Cuba
- InvisibleFerret
- Ragnar Locker
- SLOTHFULMEDIA
- Medusa Ransomware
- MegaCortex
- VIRTUALPITA
- Industroyer
- KillDisk
- AvosLocker
- HotCroissant
- BlackByte 2.0 Ransomware
- EKANS
- LockBit 3.0
- ROADSWEEP
- Pysa
- HermeticWiper
- Maze
- Netwalker
- DRYHOOK
- BRICKSTORM
- INC Ransomware
- RansomHub
- Akira _v2