1200KM / detection
T1489 Service Stop — Detection Rules
Detection workspace for T1489 Service Stop: 19 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Azure Application Deleted · test · medium · {"product":"azure","service":"activitylogs"}
- Azure Container Registry Created or Deleted · test · low · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes Cluster Created or Deleted · test · low · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes Network Policy Change · test · medium · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes Sensitive Role Access · test · medium · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes RoleBinding/ClusterRoleBinding Modified and Deleted · test · medium · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes Secret or Config Object Access · test · medium · {"product":"azure","service":"activitylogs"}
- Azure Kubernetes Service Account Modified or Deleted · test · medium · {"product":"azure","service":"activitylogs"}
- Potential Abuse of Linux Magic System Request Key · experimental · medium · {"product":"linux","service":"auditd","definition":"Required auditd configuration:\n-w /proc/sysrq-trigger -p wa -k sysrq\n-w /proc/sys/kernel/sysrq -p wa -k sysrq\n"}
- Disable Or Stop Services · test · medium · {"category":"process_creation","product":"linux"}
- Application Uninstalled · test · low · {"product":"windows","service":"application"}
- Important Scheduled Task Deleted or Disabled · test · high · {"product":"windows","service":"taskscheduler","definition":"Requirements: The \"Microsoft-Windows-TaskScheduler/Operational\" is disabled by default and needs to be enabled in order for this detection to trigger"}
- Stop Windows Service Via Net.EXE · test · low · {"category":"process_creation","product":"windows"}
- Stop Windows Service Via PowerShell Stop-Service · test · low · {"category":"process_creation","product":"windows"}
- Stop Windows Service Via Sc.EXE · test · low · {"category":"process_creation","product":"windows"}
- Delete Important Scheduled Task · test · high · {"category":"process_creation","product":"windows"}
- Delete All Scheduled Tasks · test · high · {"category":"process_creation","product":"windows"}
- Disable Important Scheduled Task · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Windows Service Tampering · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0021 Behavioral Detection for Service Stop across Platforms
AN0061 Analytic 0061
Adversary disables or stops critical services (e.g., Exchange, SQL, AV, endpoint monitoring) using native utilities or API calls, often preceding destructive actions (T1485, T1486). Behavioral chain: Elevated execution context + stop-service or sc.exe or ChangeServiceConfigW + terminated or disabled service + possible follow-up file manipulation.
AN0062 Analytic 0062
Adversary executes systemctl or service stop targeting high-value services (e.g., mysql, sshd), possibly followed by rm or shred against data stores. Behavioral chain: sudo/su usage + stop command + /var/log/messages or syslog entries + file access/delete.
AN0063 Analytic 0063
Use of launchctl to stop services or kill critical background processes (e.g., securityd, com.apple.*), typically followed by command-line tools like rm or diskutil. Behavioral chain: Terminal or remote shell + launchctl bootout/disable + process termination + follow-on modification.
AN0064 Analytic 0064
Attacker disables VM-related services or stops VMs forcibly to target vmdk or logs. Behavioral chain: esxcli or vim-cmd stop + audit log showing user privilege use + datastore file manipulation.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- File Deletion · DC0040
- Logon Session Metadata · DC0088
- Process Creation · DC0032
- Process Termination · DC0033
- Service Creation · DC0060
- Service Metadata · DC0041
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.