Detection Playbook: Service Stop (T1489)
Service Stop (T1489) is a technique where adversaries deliberately halt or disable running services on a target system to prevent legitimate users from acces…
Threat Intelligence for Every Defender
Daily MITRE ATT&CK-based detection playbooks covering common adversary techniques. Each playbook includes SIEM-agnostic detection logic and investigation and response guidance.
Service Stop (T1489) is a technique where adversaries deliberately halt or disable running services on a target system to prevent legitimate users from acces…
Inhibit System Recovery (T1490) describes adversary actions taken to delete, disable, or corrupt the built-in recovery mechanisms of an operating system or p…
Data Encrypted for Impact (T1486) describes adversary activity where files, drives, or entire systems are encrypted to deny the victim access to their own da…
Valid Accounts (T1078) describes adversaries using legitimate, existing credentials — stolen, purchased, phished, or brute-forced — to access systems and ser…
Spearphishing Link (T1566.002) is a targeted email attack where adversaries send carefully crafted messages containing malicious URLs to specific individuals…
Spearphishing Attachment (T1566.001) is a targeted email-based attack where an adversary sends a crafted email to a specific individual, company, or industry…
Service Execution (T1569.002) describes how adversaries abuse the Windows Service Control Manager (SCM) to run malicious commands or payloads — either by cre…
SMB/Windows Admin Shares (T1021.002) is a lateral movement technique where attackers use valid credentials — stolen, brute-forced, or obtained through creden…
Remote Desktop Protocol (RDP) lateral movement occurs when an adversary uses valid credentials to interactively log into a remote Windows system via port 338…
System Information Discovery (T1082) is a technique where adversaries enumerate detailed information about a target system — including OS version, patch leve…