1200KM / simulation
T1007 System Service Discovery — Attack Simulation
Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as sc query, tasklist /svc, systemctl --type=service, and net start. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS. Adversaries may use the information from System Service…
Technique description
Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as sc query, tasklist /svc, systemctl --type=service, and net start. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS. Adversaries may use the information from System Service…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Get-Service Execution
Procedure 51f17016-d8fa-4360-888a-df4bf92c4a04; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Service Discovery - net.exe
Procedure 5f864a3f-8ce9-45c0-812c-bdf7d8aeacc3; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- System Service Discovery - Windows Scheduled Tasks (schtasks)
Procedure 7cd7eaa3-9ccc-460d-96d2-c6fb13e6d58a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Service Discovery
Procedure 89676ba1-b1f8-47ee-b940-2e1a113ebc71; elevation required; cleanup not declared. Not executed or individually validated.
- System Service Discovery - Linux init scripts
Procedure 8f2a5d2b-4018-46d4-8f3f-0fea53754690; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Service Discovery - macOS launchctl
Procedure 9b378962-a75e-4856-b117-2503d6dcebba; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Service Discovery - Services Registry Enumeration
Procedure d70d82bd-bb00-4837-b146-b40d025551b2; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Service Discovery - systemctl/service
Procedure f4b26bce-4c2c-46c0-bcc5-fce062d38bef; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.