T1007Techniquediscoveryagent-callable

T1007System Service Discovery

Platforms: Windows · macOS · Linux

ATT&CK version: 14.1

What it is

Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as <code>sc query</code>, <code>tasklist /svc</code>, <code>systemctl --type=service</code>, and <code>net start</code>. Adversaries may use the information from [System Service Discovery](https://attack.mitre.org/techniques/T1007) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

ATT&CK tactics· 1

Discovery

References

  1. https://attack.mitre.org/techniques/T1007
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.
T1007: System Service Discovery | SQUR Knowledge Base