// MITRE ATT&CK
T1489 · Service Stop
Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment.(Citation: Talos Olympic ...
¿Cómo detectarlo y mitigarlo?
La detección de Service Stop parte de la telemetría de tu SIEM/EDR. Escribe una regla de detección con el generador Sigma, analiza logs sospechosos en el analizador de logs y sitúa la técnica en tu cobertura con la matriz ATT&CK.
Técnicas relacionadas
T1561.002
Disk Structure Wipe T1498.001
Direct Network Flood T1491.002
External Defacement T1499.001
OS Exhaustion Flood T1485.001
Lifecycle-Triggered Deletion T1496.003
SMS Pumping T1499.003
Application Exhaustion Flood T1561
Disk Wipe
Disk Structure Wipe T1498.001
Direct Network Flood T1491.002
External Defacement T1499.001
OS Exhaustion Flood T1485.001
Lifecycle-Triggered Deletion T1496.003
SMS Pumping T1499.003
Application Exhaustion Flood T1561
Disk Wipe
Fuente: MITRE ATT&CK®. ATT&CK es una marca registrada de The MITRE Corporation. Contenido con fines educativos.