ATT&CK · T1007
System Service Discovery
Tactics: discovery
About
Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as <code>sc query</code>, <code>tasklist /svc</code>, <code>systemctl --type=service</code>, and <code>net start</code>. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS. Adversaries may use the information from System Service Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Used by actors
15 known groups
Software
52 malware/tools implement this
Corpus indicators tagged with this technique
16 indicators in the corpus carry T1007.
| Indicator | Type | Family | Sev | Src |
|---|---|---|---|---|
| 7ee17efef04bb7c9de90d5210263ed6993f867e5a11f86e65e3bb1362c7de237 | sha256 | ransomware | 80 | 1 |
| 9ca9432b0d29204cb5420a1a6b01533d4552130c2a8a5ecd7837efadefb4a046 | sha256 | ransomware | 80 | 1 |
| c277ae5a4dd62f51de5278790796cd2700de7f77ea17762e97729f27872d076b | sha256 | ransomware | 80 | 1 |
| ffdc194775b2904564bbbd1cf0eb01d1a01f83ef5197d1612b6e2d69de7a4732 | sha256 | — | 80 | 1 |
| 686292c07e33c4a5ca456db446bb71fb9fc67a81 | sha1 | — | 78 | 1 |
| f9eed2f0158dc98e7012fb809152209c | md5 | — | 76 | 1 |
| b103cd21280b4061f88b2bcc51394894 | md5 | — | 76 | 1 |
| ee4ff46ddd8489e81447962f927bc3f6 | md5 | — | 76 | 1 |
| 0cfdffc56f0fa325d0c4d24780b46597 | md5 | — | 76 | 1 |
| 16c211c96735f2fae9361b89bd7a31bf | md5 | — | 76 | 1 |
| 1bfe2b9493128574907a8279256a8bcc | md5 | — | 76 | 1 |
| 41c938b3cd7e55d4077e34976929b140 | md5 | — | 76 | 1 |
| 6001829a128fe264b4403138700c11a8 | md5 | — | 76 | 1 |
| 9f5606a0755bc633b9bd7db6d179c09e | md5 | — | 76 | 1 |
| 5.39.253.206 | ip | — | 70 | 1 |
| 176.32.34.135 | ip | — | 70 | 1 |