1200KM / detection
T0881 Service Stop — Detection Rules
Detection workspace for T0881 Service Stop: 0 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
No reviewed association in this snapshot.
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0765 Detection of Service Stop
AN1897 Analytic 1897
Monitor for changes made to files that may stop or disable services on a system to render those services unavailable to legitimate users. Monitor executed commands and arguments that may stop or disable services on a system to render those services unavailable to legitimate users. Remote access tools with built-in features may interact directly with the Windows API to perform these functions outside of typical system utilities. For example, ChangeServiceConfigW may be used by an adversary to prevent services from starting. For added context on adversary procedures and background see Service Stop. Monitor processes and command-line arguments to see if critical processes are terminated or stop running. For added context on adversary procedures and background see Service Stop. Alterations to the service binary path or the service startup type changed to disabled may be suspicious. Monitor for changes made to Windows registry keys and/or values that may stop or disable services on a system to render those services unavailable to legitimate users. Monitor for newly executed processes that may stop or disable services on a system to render those services unavailable to legitimate users.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Command Execution · DC0064
- File Modification · DC0061
- OS API Execution · DC0021
- Process Creation · DC0032
- Process Termination · DC0033
- Service Metadata · DC0041
- Windows Registry Key Modification · DC0063
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.