Real-world descriptions of how a group, tool or campaign used a technique.
52 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1007 System Service Discovery |
MalwareTrickBot | TrickBot collects a list of install programs and services on the system’s machine. |
| T1007 System Service Discovery |
MalwareSynAck | SynAck enumerates all running services. |
| T1007 System Service Discovery |
MalwareSardonic | Sardonic has the ability to execute the `net start` command. |
| T1007 System Service Discovery |
MalwareEmissary | Emissary has the capability to execute the command |
| T1007 System Service Discovery |
MalwareUrsnif | Ursnif has gathered information about running services. |
| T1007 System Service Discovery |
MalwareZLib | ZLib has the ability to discover and manipulate Windows services. |
| T1007 System Service Discovery |
MalwareGeminiDuke | GeminiDuke collects information on programs and services on the victim that are configured to automatically run at startup. |
| T1007 System Service Discovery |
MalwareGravityRAT | GravityRAT has a feature to list the available services on the system. |
| T1007 System Service Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has leveraged an encoded list of services that it designates for termination. |
| T1007 System Service Discovery |
MalwareRainyDay | RainyDay can create and register a service for execution. |
| T1007 System Service Discovery |
MalwareGreyEnergy | GreyEnergy enumerates all Windows services. |
| T1007 System Service Discovery |
MalwarePUBLOAD | PUBLOAD has leveraged `tasklist` to gather running services on victim host. |
| T1007 System Service Discovery |
MalwareSombRAT | SombRAT can enumerate services on a victim machine. |
| T1007 System Service Discovery |
MalwareInvisiMole | InvisiMole can obtain running services on the victim. |
| T1007 System Service Discovery |
MalwareVolgmer | Volgmer queries the system to identify existing services. |
| T1007 System Service Discovery |
MalwareWINERACK | WINERACK can enumerate services. |
| T1007 System Service Discovery |
MalwareHyperBro | HyperBro can list all services and their configurations. |
| T1007 System Service Discovery |
MalwareDarkTortilla | DarkTortilla can retrieve information about a compromised system's running services. |
| T1007 System Service Discovery |
MalwareBabuk | Babuk can enumerate all services running on a compromised host. |
| T1007 System Service Discovery |
MalwareDyre | Dyre has the ability to identify running services on a compromised host. |
| T1007 System Service Discovery |
MalwareBBSRAT | BBSRAT can query service configuration information. |
| T1007 System Service Discovery |
MalwareS-Type | S-Type runs the command |
| T1007 System Service Discovery |
MalwareSykipot | Sykipot may use |
| T1007 System Service Discovery |
MalwareEpic | Epic uses the |
| T1007 System Service Discovery |
MalwareCuba | Cuba can query service status using |
| T1007 System Service Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can monitor services. |
| T1007 System Service Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can obtain a list of the services from a system. |
| T1007 System Service Discovery |
MalwareElise | Elise executes |
| T1007 System Service Discovery |
MalwareEmbargo | Embargo has obtained active services running on the victim’s system through the functions `OpenSCManagerW()` and `EnumServicesStatusExW()`. |
| T1007 System Service Discovery |
MalwareIxeshe | Ixeshe can list running services. |
| T1007 System Service Discovery |
MalwareBlack Basta | Black Basta can check whether the service name `FAX` is present. |
| T1007 System Service Discovery |
MalwareRATANKBA | RATANKBA uses |
| T1007 System Service Discovery |
MalwareCobalt Strike | Cobalt Strike can enumerate services on compromised hosts. |
| T1007 System Service Discovery |
MalwareSUNBURST | SUNBURST collected a list of service names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists. |
| T1007 System Service Discovery |
MalwareHotCroissant | HotCroissant has the ability to retrieve a list of services on the infected host. |
| T1007 System Service Discovery |
MalwareREvil | REvil can enumerate active services. |
| T1007 System Service Discovery |
MalwareSysUpdate | SysUpdate can collect a list of services on a victim machine. |
| T1007 System Service Discovery |
MalwareKwampirs | Kwampirs collects a list of running services with the command |
| T1007 System Service Discovery |
MalwareLAMEHUG | LAMEHUG can gather service information on targeted systems. |
| T1007 System Service Discovery |
MalwareLookBack | LookBack can enumerate services on the victim machine. |
| T1007 System Service Discovery |
MalwareZxShell | ZxShell can check the services on the system. |
| T1007 System Service Discovery |
MalwareJPIN | JPIN can list running services. |
| T1007 System Service Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor can check if it is running as a service on a compromised host. |
| T1007 System Service Discovery |
MalwareQilin | Qilin can identify specific services for termination or to be left running at execution. |
| T1007 System Service Discovery |
MalwarejRAT | jRAT can list local services. |
| T1007 System Service Discovery |
MalwareComnie | Comnie runs the command: |
| T1007 System Service Discovery |
MalwareBitPaymer | BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem. |
| T1007 System Service Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has the capability to enumerate services. |
| T1007 System Service Discovery |
ToolNet | The |
| T1007 System Service Discovery |
ToolSILENTTRINITY | SILENTTRINITY can search for modifiable services that could be used for privilege escalation. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.