Real-world descriptions of how a group, tool or campaign used a technique.
15 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
GroupIndrik Spider | Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system. |
| T1007 System Service Discovery |
GroupKimsuky | Kimsuky has used an instrumentor script to gather the names of all services running on a victim's system. |
| T1007 System Service Discovery |
Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to obtain information about services: |
| T1007 System Service Discovery |
GroupVolt Typhoon | Volt Typhoon has used `net start` to list running services. |
| T1007 System Service Discovery |
GroupTeamTNT | TeamTNT has searched for services such as Alibaba Cloud Security's aliyun service and BMC Helix Cloud Security's bmc-agent service in order to disable them. |
| T1007 System Service Discovery |
GroupOilRig | OilRig has used |
| T1007 System Service Discovery |
GroupAquatic Panda | Aquatic Panda has attempted to discover services for third party EDR products. |
| T1007 System Service Discovery |
GroupKe3chang | Ke3chang performs service discovery using |
| T1007 System Service Discovery |
GroupAPT1 | APT1 used the commands |
| T1007 System Service Discovery |
GroupTurla | Turla surveys a system upon check-in to discover running services and associated processes using the |
| T1007 System Service Discovery |
GroupPoseidon Group | After compromising a victim, Poseidon Group discovers all running services. |
| T1007 System Service Discovery |
GroupChimera | Chimera has used |
| T1007 System Service Discovery |
GroupMirrorFace | MirrorFace has used Tasklist for discovery post compromise. |
| T1007 System Service Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has used TROJ_GETVERSION to discover system services. |
| T1007 System Service Discovery |
GroupEarth Lusca | Earth Lusca has used Tasklist to obtain information from a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.