ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1007×

15 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
GroupIndrik Spider

Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system.

T1007
System Service Discovery
GroupKimsuky

Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system.

T1007
System Service Discovery
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to obtain information about services: net start >> %temp%\download

T1007
System Service Discovery
GroupVolt Typhoon

Volt Typhoon has used `net start` to list running services.

T1007
System Service Discovery
GroupTeamTNT

TeamTNT has searched for services such as Alibaba Cloud Security's aliyun service and BMC Helix Cloud Security's bmc-agent service in order to disable them.

T1007
System Service Discovery
GroupOilRig

OilRig has used sc query on a victim to gather information about services.

T1007
System Service Discovery
GroupAquatic Panda

Aquatic Panda has attempted to discover services for third party EDR products.

T1007
System Service Discovery
GroupKe3chang

Ke3chang performs service discovery using net start commands.

T1007
System Service Discovery
GroupAPT1

APT1 used the commands net start and tasklist to get a listing of the services on the system.

T1007
System Service Discovery
GroupTurla

Turla surveys a system upon check-in to discover running services and associated processes using the tasklist /svc command.

T1007
System Service Discovery
GroupPoseidon Group

After compromising a victim, Poseidon Group discovers all running services.

T1007
System Service Discovery
GroupChimera

Chimera has used net start and net use for system service discovery.

T1007
System Service Discovery
GroupMirrorFace

MirrorFace has used Tasklist for discovery post compromise.

T1007
System Service Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has used TROJ_GETVERSION to discover system services.

T1007
System Service Discovery
GroupEarth Lusca

Earth Lusca has used Tasklist to obtain information from a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.