MITRE ATT&CK Technique
T1007System Service Discovery
- First Reported
- Jul 14, 2025
- Latest Reported
- Sep 10, 2026
Official Description
Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as <code>sc query</code>, <code>tasklist /svc</code>, <code>systemctl --type=service</code>, and <code>net start</code>. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS.(Citation: Elastic Security Labs GOSAR 2024)(Citation: SentinelLabs macOS Malware 2021)(Citation: Splunk Linux Gormir 2024)(Citation: Aquasec Kinsing 2020)
Adversaries may use the information from [System Service Discovery](https://attack.mitre.org/techniques/T1007) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Adversaries may use the information from [System Service Discovery](https://attack.mitre.org/techniques/T1007) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
- Tactics
- Discovery
- Platforms
- Linux, macOS, Windows
- MITRE Version
- 1.6
- Last Modified
- May 12, 2026
Reported Context (2)
- The built-in Get-Service handler enumerates Windows services. Zscaler Details SloppyRAT, a New Malware Linked to Ransomware Attacks
- The RAT used Get-Service to enumerate Windows services. KongTuke FileFix Campaign Delivers a New PHP-Based Interlock RAT
Malware (5)
Threat Actors (3)
MITRE ATT&CK (35)
Vendors (2)
Products (9)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.