System Service Discovery T1007
Tactic: Discovery
Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as sc query, tasklist /svc, systemctl --type=service, and net start. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS.
Events covered
4 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 25 rules share fields, values, and exclusions.
Fields filtered most (20 distinct)
These fields appear most often in rule filters.
Top indicator values (245 distinct)
These values appear most often in rule predicates.
Exclusions (44 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Domain: Endpoint
Sigma 11 rules
- Crontab Enumeration
- ESXi Network Configuration Discovery Via ESXCLI
- ESXi Storage Information Discovery Via ESXCLI
- ESXi System Information Discovery Via ESXCLI
- ESXi VM List Discovery Via ESXCLI
- ESXi VSAN Information Discovery Via ESXCLI
- HackTool - PCHunter Execution
- Net.EXE Execution
- Potential Configuration And Service Reconnaissance Via Reg.EXE
- Potential Registry Reconnaissance Via PowerShell Script
- SC.EXE Query Execution
Elastic 4 rules
- Deprecated - PowerShell Script with Discovery Capabilities
- Enumeration Command Spawned via WMIPrvSE
- PowerShell Suspicious Discovery Related Windows API Functions
- System Service Discovery through built-in Windows Utilities
Splunk 10 rules
- Common Active Directory Commands (PowerShell)
- Common Active Directory Commands (Sysmon)
- Common Active Directory Commands (Windows Event Log)
- Common Recon Commands in Short Burst (Sysmon)
- Common Recon Commands in Short Burst (Windows Event Log)
- Common Reconnaissance Commands (PowerShell)
- Common Reconnaissance Commands (Sysmon)
- Common Reconnaissance Commands (Windows Event Log)
- Windows Net System Service Discovery
- Windows WinPEAS PowerShell Script Execution