TACTIC: DISCOVERY

System Service Discovery (T1007): real cases

MITRE Definition ↗
Adversaries list configured system services to find exploitable software paths and vulnerable configurations.

Key Facts

Technique ID
T1007
Discovery
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1007.
  • Tactical Phase: Discovery.
  • Substantiated in 1 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Plea Agreement ¶ 5, Page 13
"Vachon-Desjardins executed net start and sc query to enumerate installed antivirus services before deploying ransomware."
U.S. District Court for the Middle District of Florida View full case dossier →