Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1007
MITRE ATT&CK Technique

T1007: System Service Discovery

ShareXLinkedInRedditHN

Adversaries may try to gather information about registered local system services. Adversaries may obtain information about services using tools as well as OS utility commands such as <code>sc query</code>, <code>tasklist /svc</code>, <code>systemctl --type=service</code>, and <code>net start</code>. Adversaries may also gather information about schedule tasks via commands such as `schtasks` on Windows or `crontab -l` on Linux and macOS.(Citation: Elastic Security Labs GOSAR 2024)(Citation: SentinelLabs macOS Malware 2021)(Citation: Splunk Linux Gormir 2024)(Citation: Aquasec Kinsing 2020) Adversaries may use the information from [System Service Discovery](https://attack.mitre.org/techniques/T1007) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Tactics
Discovery
Platforms
Linux, macOS, Windows

▪Used by groups (15)

G0004Ke3changG0006APT1G0010TurlaG0018admin@338G0033Poseidon GroupG0049OilRigG0060BRONZE BUTLERG0094KimsukyG0114ChimeraG0119Indrik SpiderG0139TeamTNTG0143Aquatic PandaG1006Earth LuscaG1017Volt TyphoonG1054MirrorFace

▪Software using this technique (52)

S0015IxeshemalwareS0018SykipotmalwareS0024DyremalwareS0039NettoolS0049GeminiDukemalwareS0057TasklisttoolS0081ElisemalwareS0082EmissarymalwareS0085S-TypemalwareS0086ZLibmalwareS0091EpicmalwareS0127BBSRATmalwareS0154Cobalt StrikemalwareS0180VolgmermalwareS0201JPINmalwareS0203HydraqmalwareS0219WINERACKmalwareS0236KwampirsmalwareS0237GravityRATmalwareS0241RATANKBAmalwareS0242SynAckmalwareS0244ComniemalwareS0260InvisiMolemalwareS0266TrickBotmalwareS0283jRATmalwareS0342GreyEnergymalwareS0378PoshC2toolS0386UrsnifmalwareS0398HyperBromalwareS0412ZxShellmalwareS0431HotCroissantmalwareS0496REvilmalwareS0533SLOTHFULMEDIAmalwareS0559SUNBURSTmalwareS0570BitPaymermalwareS0572Caterpillar WebShellmalwareS0582LookBackmalwareS0615SombRATmalwareS0625CubamalwareS0629RainyDaymalwareS0638BabukmalwareS0663SysUpdatemalwareS0692SILENTTRINITYtoolS1027Heyoka BackdoormalwareS1066DarkTortillamalwareS1070Black BastamalwareS1085SardonicmalwareS1228PUBLOADmalwareS1242QilinmalwareS1244Medusa RansomwaremalwareS1247EmbargomalwareS9035LAMEHUGmalware

▪Reference

T1007on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.