Service Stop
Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment.(Citation: Talos Olympic Destroyer 2018)(Citation: Novetta Blockbuster) Adversaries may accomplish this by disabling individual services of high importance to an organization, such as <code>MSExchangeIS</code>, which will m...
BY SOURCE
PROCEDURES (27)
Auto-extracted: 7 detections for persist
Auto-extracted: 6 detections for general monitoring
Auto-extracted: 4 detections for cloud monitoring
Auto-extracted: 3 detections for service
Auto-extracted: 3 detections for service
Auto-extracted: 3 detections for kubernetes
Auto-extracted: 2 detections for azure
Auto-extracted: 2 detections for bypass
Auto-extracted: 2 detections for scheduled task
Auto-extracted: 2 detections for service
Auto-extracted: 2 detections for powershell
Auto-extracted: 2 detections for suspicious
Auto-extracted: 2 detections for registry
Auto-extracted: 1 detections for ransomware
Auto-extracted: 1 detections for ransomware
Auto-extracted: 1 detections for kubernetes
Auto-extracted: 1 detections for service
Auto-extracted: 1 detections for azure
Auto-extracted: 1 detections for ransomware
Auto-extracted: 1 detections for process creation monitoring
Auto-extracted: 1 detections for service monitoring
Auto-extracted: 1 detections for suspicious
Auto-extracted: 1 detections for cloud
Auto-extracted: 1 detections for cloud
Auto-extracted: 1 detections for scheduled task
Auto-extracted: 1 detections for bypass
Auto-extracted: 1 detections for container