ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1007×

52 examples

TechniqueUsed byProcedure example
T1007
System Service Discovery
MalwareTrickBot

TrickBot collects a list of install programs and services on the system’s machine.

T1007
System Service Discovery
MalwareSynAck

SynAck enumerates all running services.

T1007
System Service Discovery
MalwareSardonic

Sardonic has the ability to execute the `net start` command.

T1007
System Service Discovery
MalwareEmissary

Emissary has the capability to execute the command net start to interact with services.

T1007
System Service Discovery
MalwareUrsnif

Ursnif has gathered information about running services.

T1007
System Service Discovery
MalwareZLib

ZLib has the ability to discover and manipulate Windows services.

T1007
System Service Discovery
MalwareGeminiDuke

GeminiDuke collects information on programs and services on the victim that are configured to automatically run at startup.

T1007
System Service Discovery
MalwareGravityRAT

GravityRAT has a feature to list the available services on the system.

T1007
System Service Discovery
MalwareMedusa Ransomware

Medusa Ransomware has leveraged an encoded list of services that it designates for termination.

T1007
System Service Discovery
MalwareRainyDay

RainyDay can create and register a service for execution.

T1007
System Service Discovery
MalwareGreyEnergy

GreyEnergy enumerates all Windows services.

T1007
System Service Discovery
MalwarePUBLOAD

PUBLOAD has leveraged `tasklist` to gather running services on victim host.

T1007
System Service Discovery
MalwareSombRAT

SombRAT can enumerate services on a victim machine.

T1007
System Service Discovery
MalwareInvisiMole

InvisiMole can obtain running services on the victim.

T1007
System Service Discovery
MalwareVolgmer

Volgmer queries the system to identify existing services.

T1007
System Service Discovery
MalwareWINERACK

WINERACK can enumerate services.

T1007
System Service Discovery
MalwareHyperBro

HyperBro can list all services and their configurations.

T1007
System Service Discovery
MalwareDarkTortilla

DarkTortilla can retrieve information about a compromised system's running services.

T1007
System Service Discovery
MalwareBabuk

Babuk can enumerate all services running on a compromised host.

T1007
System Service Discovery
MalwareDyre

Dyre has the ability to identify running services on a compromised host.

T1007
System Service Discovery
MalwareBBSRAT

BBSRAT can query service configuration information.

T1007
System Service Discovery
MalwareS-Type

S-Type runs the command net start on a victim.

T1007
System Service Discovery
MalwareSykipot

Sykipot may use net start to display running services.

T1007
System Service Discovery
MalwareEpic

Epic uses the tasklist /svc command to list the services on the system.

T1007
System Service Discovery
MalwareCuba

Cuba can query service status using QueryServiceStatusEx function.

T1007
System Service Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can monitor services.

T1007
System Service Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of the services from a system.

T1007
System Service Discovery
MalwareElise

Elise executes net start after initial communication is made to the remote server.

T1007
System Service Discovery
MalwareEmbargo

Embargo has obtained active services running on the victim’s system through the functions `OpenSCManagerW()` and `EnumServicesStatusExW()`.

T1007
System Service Discovery
MalwareIxeshe

Ixeshe can list running services.

T1007
System Service Discovery
MalwareBlack Basta

Black Basta can check whether the service name `FAX` is present.

T1007
System Service Discovery
MalwareRATANKBA

RATANKBA uses tasklist /svc to display running tasks.

T1007
System Service Discovery
MalwareCobalt Strike

Cobalt Strike can enumerate services on compromised hosts.

T1007
System Service Discovery
MalwareSUNBURST

SUNBURST collected a list of service names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists.

T1007
System Service Discovery
MalwareHotCroissant

HotCroissant has the ability to retrieve a list of services on the infected host.

T1007
System Service Discovery
MalwareREvil

REvil can enumerate active services.

T1007
System Service Discovery
MalwareSysUpdate

SysUpdate can collect a list of services on a victim machine.

T1007
System Service Discovery
MalwareKwampirs

Kwampirs collects a list of running services with the command tasklist /svc.

T1007
System Service Discovery
MalwareLAMEHUG

LAMEHUG can gather service information on targeted systems.

T1007
System Service Discovery
MalwareLookBack

LookBack can enumerate services on the victim machine.

T1007
System Service Discovery
MalwareZxShell

ZxShell can check the services on the system.

T1007
System Service Discovery
MalwareJPIN

JPIN can list running services.

T1007
System Service Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can check if it is running as a service on a compromised host.

T1007
System Service Discovery
MalwareQilin

Qilin can identify specific services for termination or to be left running at execution.

T1007
System Service Discovery
MalwarejRAT

jRAT can list local services.

T1007
System Service Discovery
MalwareComnie

Comnie runs the command: net start >> %TEMP%\info.dat on a victim.

T1007
System Service Discovery
MalwareBitPaymer

BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem.

T1007
System Service Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has the capability to enumerate services.

T1007
System Service Discovery
ToolNet

The net start command can be used in Net to find information about Windows services.

T1007
System Service Discovery
ToolSILENTTRINITY

SILENTTRINITY can search for modifiable services that could be used for privilege escalation.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.