Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Impact/ T1489

T1489Service Stop

T1489 — Service Stop is a MITRE ATT&CK technique in the Impact tactic. Clankerusecase tracks 20 detection use cases covering it and 1 threat-intel article citing it.

Impact
View on the matrix → Filter Detection Library MITRE official spec ↗
20Use cases
1Articles
0Sub-techniques
1Tactic

Use cases covering this technique (20)

Ollama Abnormal Service Crash Availability Attack ESCU actions · hunting P Excessive Attempt To Disable Services ESCU actions · hunting P Linux Auditd Auditd Service Stop ESCU actions · hunting P Linux Auditd Osquery Service Stop ESCU actions · hunting P Linux Auditd Stop Services ESCU actions · hunting P Linux Auditd Sysmon Service Stop ESCU actions · hunting P Linux Disable Services ESCU actions · alerting P Linux Magic SysRq Key Abuse ESCU actions · alerting P Linux Stop Services ESCU actions · alerting P Windows Excessive Service Stop Attempt ESCU actions · alerting P Windows Processes Killed By Industroyer2 Malware ESCU actions · hunting P Windows Security Account Manager Stopped ESCU actions · alerting P Windows Service Deletion In Registry ESCU actions · hunting P Windows Service Stop Attempt ESCU actions · hunting P Windows Service Stop By Deletion ESCU actions · hunting P Windows Service Stop Win Updates ESCU actions · hunting P Windows Set Account Password Policy To Unlimited Via Net ESCU actions · hunting P Excessive Service Stop Attempt ESCU actions · hunting P Windows Service Stop Via Net and SC Application ESCU actions · hunting P Windows Valid Account With Never Expires Password ESCU actions · alerting P

Articles citing this technique (1)