Technique.View on attack.mitre.org
Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as sc query, tasklist /svc, systemctl --type=service, and net start. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS.
Adversaries may use the information from System Service Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Rules on DetectionCode tagged with T1007.
| Rule | Level | Log source |
|---|---|---|
| HackTool - PCHunter Execution | high | windows / process_creation |
| ESXi Network Configuration Discovery Via ESXCLI | medium | linux / process_creation |
| ESXi Storage Information Discovery Via ESXCLI | medium | linux / process_creation |
| ESXi System Information Discovery Via ESXCLI | medium | linux / process_creation |
| ESXi VM List Discovery Via ESXCLI | medium | linux / process_creation |
| ESXi VSAN Information Discovery Via ESXCLI | medium | linux / process_creation |
| Potential Configuration And Service Reconnaissance Via Reg.EXE | medium | windows / process_creation |
| Crontab Enumeration | low | linux / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Net System Service Discovery | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows WinPEAS PowerShell Script Execution | TTP | NULL | Powershell Script Block Logging 4104 |
| Used by | Procedure example |
|---|---|
| Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to obtain information about services: |
| GroupAPT1 | APT1 used the commands |
| GroupAquatic Panda | Aquatic Panda has attempted to discover services for third party EDR products. |
| GroupBRONZE BUTLER | BRONZE BUTLER has used TROJ_GETVERSION to discover system services. |
| GroupChimera | Chimera has used |
| GroupEarth Lusca | Earth Lusca has used Tasklist to obtain information from a compromised host. |
| GroupIndrik Spider | Indrik Spider has used the win32_service WMI class to retrieve a list of services from the system. |
| GroupKe3chang | Ke3chang performs service discovery using |
| Used by | Procedure example |
|---|---|
| MalwareBabuk | Babuk can enumerate all services running on a compromised host. |
| MalwareBBSRAT | BBSRAT can query service configuration information. |
| MalwareBitPaymer | BitPaymer can enumerate existing Windows services on the host that are configured to run as LocalSystem. |
| MalwareBlack Basta | Black Basta can check whether the service name `FAX` is present. |
| MalwareCaterpillar WebShell | Caterpillar WebShell can obtain a list of the services from a system. |
| MalwareCobalt Strike | Cobalt Strike can enumerate services on compromised hosts. |
| MalwareComnie | Comnie runs the command: |
| MalwareCuba | Cuba can query service status using |
| Used by | Procedure example |
|---|---|
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net start` command as part of their initial reconnaissance. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used the `tasklist` command to search for one of its backdoors. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.