System Service Discovery

T1007

Technique.View on attack.mitre.org

About this technique

Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as sc query, tasklist /svc, systemctl --type=service, and net start. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS.

Adversaries may use the information from System Service Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Detection rules10

Rules on DetectionCode tagged with T1007.

Sigma8

RuleLevelLog source
HackTool - PCHunter Executionhighwindows / process_creation
ESXi Network Configuration Discovery Via ESXCLImediumlinux / process_creation
ESXi Storage Information Discovery Via ESXCLImediumlinux / process_creation
ESXi System Information Discovery Via ESXCLImediumlinux / process_creation
ESXi VM List Discovery Via ESXCLImediumlinux / process_creation
ESXi VSAN Information Discovery Via ESXCLImediumlinux / process_creation
Potential Configuration And Service Reconnaissance Via Reg.EXEmediumwindows / process_creation
Crontab Enumerationlowlinux / process_creation

Splunk2

RuleTypeRiskData source
Windows Net System Service DiscoveryHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows WinPEAS PowerShell Script ExecutionTTPNULLPowershell Script Block Logging 4104

Groups15

Software52

Show 28 more

Campaigns2

Procedure examples69

Groups15

Used byProcedure example
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to obtain information about services: net start >> %temp%\download

GroupAPT1

APT1 used the commands net start and tasklist to get a listing of the services on the system.

GroupAquatic Panda

Aquatic Panda has attempted to discover services for third party EDR products.

GroupBRONZE BUTLER

BRONZE BUTLER has used TROJ_GETVERSION to discover system services.

GroupChimera

Chimera has used net start and net use for system service discovery.

GroupEarth Lusca

Earth Lusca has used Tasklist to obtain information from a compromised host.

GroupIndrik Spider

Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system.

GroupKe3chang

Ke3chang performs service discovery using net start commands.

View all 15 groups examples

Software52

Used byProcedure example
MalwareBabuk

Babuk can enumerate all services running on a compromised host.

MalwareBBSRAT

BBSRAT can query service configuration information.

MalwareBitPaymer

BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem.

MalwareBlack Basta

Black Basta can check whether the service name `FAX` is present.

MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of the services from a system.

MalwareCobalt Strike

Cobalt Strike can enumerate services on compromised hosts.

MalwareComnie

Comnie runs the command: net start >> %TEMP%\info.dat on a victim.

MalwareCuba

Cuba can query service status using QueryServiceStatusEx function.

View all 52 software examples

Campaigns2

Used byProcedure example
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net start` command as part of their initial reconnaissance.

CampaignOperation Wocao

During Operation Wocao, threat actors used the `tasklist` command to search for one of its backdoors.

References4

  1. Aquasec Kinsing 2020 Open source
    Gal Singer. (2020, April 3). Threat Alert: Kinsing Malware Attacks Targeting Container Environments. Retrieved May 22, 2025.
  2. Elastic Security Labs GOSAR 2024 Open source
    Jia Yu Chan, Salim Bitam, Daniel Stepanic, and Seth Goodwin. (2024, December 12). Under the SADBRIDGE with GOSAR: QUASAR Gets a Golang Rewrite. Retrieved May 22, 2025.
  3. SentinelLabs macOS Malware 2021 Open source
    Phil Stokes. (2021, February 16). 20 Common Tools & Techniques Used by macOS Threat Actors & Malware. Retrieved May 22, 2025.
  4. Splunk Linux Gormir 2024 Open source
    Splunk Threat Research Team , Teoderick Contreras. (2024, July 15). Breaking Down Linux.Gomir: Understanding this Backdoor’s TTPs. Retrieved May 22, 2025.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.