Technique.View on attack.mitre.org
Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment.
Adversaries may accomplish this by disabling individual services of high importance to an organization, such as MSExchangeIS, which will make Exchange content inaccessible. In some cases, adversaries may stop or disable many or all services to render systems unusable. Services or processes may not allow for modification of their data stores while running. Adversaries may stop services or processes in order to conduct Data Destruction or Data Encrypted for Impact on the data stores of services like Exchange and SQL Server, or on virtual machines hosted on ESXi infrastructure.
Threat actors may also disable or stop service in cloud environments. For example, by leveraging the `DisableAPIServiceAccess` API in AWS, a threat actor may prevent the service from creating service-linked roles on new accounts in the AWS Organization.
Rules on DetectionCode tagged with T1489.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Excessive Attempt To Disable Services | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Excessive Service Stop Attempt | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Linux Auditd Auditd Service Stop | Anomaly | NULL | Linux Auditd Service Stop |
| Linux Auditd Osquery Service Stop | Anomaly | NULL | Linux Auditd Service Stop |
| Linux Auditd Stop Services | Hunting | NULL | Linux Auditd Service Stop |
| Linux Auditd Sysmon Service Stop | Anomaly | NULL | Linux Auditd Service Stop |
| Linux Disable Services | TTP | NULL | Sysmon for Linux EventID 1 |
| Linux Magic SysRq Key Abuse | TTP | NULL | Linux Auditd Path, Linux Auditd Cwd |
| Linux Stop Services | TTP | NULL | Sysmon for Linux EventID 1 |
| Ollama Abnormal Service Crash Availability Attack | Anomaly | NULL | Ollama Server |
| Windows Excessive Service Stop Attempt | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Processes Killed By Industroyer2 Malware | Anomaly | NULL | Sysmon EventID 5 |
| Windows Security Account Manager Stopped | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Service Deletion In Registry | Anomaly | NULL | Sysmon EventID 13 |
| Windows Service Stop Attempt | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Service Stop By Deletion | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Service Stop Via Net and SC Application | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Service Stop Win Updates | Anomaly | NULL | Windows Event Log System 7040 |
| Windows Set Account Password Policy To Unlimited Via Net | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Valid Account With Never Expires Password | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupIndrik Spider | Indrik Spider has used PsExec to stop services prior to the execution of ransomware. |
| GroupKimsuky | Kimsuky has disabled actively running virtual environments using the `KillMe` function to include VMware, Microsoft Hypervisors, and VirtualBox. |
| GroupLAPSUS$ | LAPSUS$ has shut down virtual machines from within a victim's on-premise VMware ESXi infrastructure. |
| GroupLazarus Group | Lazarus Group has stopped the MSExchangeIS service to render Exchange contents inaccessible to users. |
| GroupMedusa Group | Medusa Group has terminated services related to backups, security, databases, communication, filesharing and websites. |
| GroupSandworm Team | Sandworm Team attempts to stop the MSSQL Windows service to ensure successful encryption of locked files. |
| GroupWizard Spider | Wizard Spider has used taskkill.exe and net.exe to stop backup, catalog, cloud, and other services prior to network encryption. |
| Used by | Procedure example |
|---|---|
| MalwareAkira _v2 | Akira _v2 can stop running virtual machines. |
| MalwareAvaddon | Avaddon looks for and attempts to stop database processes. |
| MalwareAvosLocker | AvosLocker has terminated specific processes before encryption. |
| MalwareBabuk | Babuk can stop specific services related to backups. |
| MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can terminate running services. |
| MalwareBlackCat | BlackCat has the ability to stop VM services on compromised networks. |
| MalwareBRICKSTORM | BRICKSTORM has terminated an existing process to ensure that its own new process can execute. |
| MalwareCheerscrypt | Cheerscrypt has the ability to terminate VM processes on compromised hosts through execution of `esxcli vm process kill`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.