1200KM / simulation
T1489 Service Stop — Attack Simulation
Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment. Adversaries may accomplish this by disabling individual services of high importance to an organization, such as MSExchangeIS, which will make Exchange content inaccessible.…
Technique description
Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment. Adversaries may accomplish this by disabling individual services of high importance to an organization, such as MSExchangeIS, which will make Exchange content inaccessible.…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Linux - Stop service by killing process using pkill
Procedure 08b4718f-a8bf-4bb5-a552-294fc5178fea; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows - iisreset.exe to stop Internet services
Procedure 0f752206-61b2-4f2f-b397-e883a503968b; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows - Stop service using Service Controller
Procedure 21dfb440-830d-4c86-a3e5-2a491d5a8d04; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Linux - Stop service by killing process using kill
Procedure 332f4c76-7e96-41a6-8cc2-7361c49db8be; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows - Stop service using net.exe
Procedure 41274289-ec9c-4213-bea4-e43c4aa57954; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Linux - Stop service using systemctl
Procedure 42e3a5bd-1e45-427f-aa08-2a65fa29a820; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Abuse of linux magic system request key for Send a SIGTERM to all processes
Procedure 6e76f56f-2373-4a6c-a63f-98b7b72761f1; elevation required; cleanup not declared. Not executed or individually validated.
- Linux - Stop service by killing process using killall
Procedure e5d95be6-02ee-4ff1-aebe-cf86013b6189; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Windows - Stop service by killing process
Procedure f3191b84-c38b-400b-867e-3a217a27795f; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.