T1007Techniquediscoveryagent-callable

T1007System Service Discovery

Platforms: Linux · macOS · Windows

ATT&CK version: v19.1

What it is

Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as <code>sc query</code>, <code>tasklist /svc</code>, <code>systemctl --type=service</code>, and <code>net start</code>. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS.(Citation: Elastic Security Labs GOSAR 2024)(Citation: SentinelLabs macOS Malware 2021)(Citation: Splunk Linux Gormir 2024)(Citation: Aquasec Kinsing 2020) Adversaries may use the information from [System Service Discovery](https://attack.mitre.org/techniques/T1007) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

ATT&CK tactics· 1

Discovery

References

  1. https://attack.mitre.org/techniques/T1007
  2. https://www.aquasec.com/blog/threat-alert-kinsing-malware-container-vulnerability/
  3. https://www.elastic.co/security-labs/under-the-sadbridge-with-gosar
  4. https://www.sentinelone.com/labs/20-common-tools-techniques-used-by-macos-threat-actors-malware/
  5. https://www.splunk.com/en_us/blog/security/breaking-down-linux-gomir-understanding-this-backdoors-ttps.html
Sourced from MITRE ATT&CK Enterprise v14.1. Curated and contextualized for EU compliance use cases by Adam Lundqvist, Founder at SQUR.