T1007: T1007
Essential information
- MITRE technique ID
T1007- Confidence
- 100/100
- Revoked
- No
- Published
- 31/05/2017 23:30
- Modified
- 10/04/2026 12:07
- Author / Source
- The MITRE Corporation
Aliases
System Service Discovery
Platforms
windows macos linux
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | discovery |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (32)
-
Earth Baku relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
EvilAI relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
The MITRE Corporation Confidence 100
[Ke3chang](https://attack.mitre.org/groups/G0004) is a threat group attributed to actors operating out of China. [Ke3chang](https://attack.mitre.org/groups/G0004) has targeted oil, government, diplomatic, military, and NGOs in Central and South America, the Caribbean,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
The MITRE Corporation Confidence 100
[OilRig](https://attack.mitre.org/groups/G0049) is a suspected Iranian threat group that has targeted Middle Eastern and international victims since at least 2014. The group has targeted a variety of sectors, including…
First seen 01/01/1970 · Last seen 16/11/5138 · -
UAT-8099 relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
UNC4466 relatedAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
admin@338 relatedThe MITRE Corporation Confidence 100
[admin@338](https://attack.mitre.org/groups/G0018) is a China-based cyber threat group. It has previously used newsworthy events as lures to deliver malware and has primarily targeted organizations involved in financial, economic, and…
First seen 01/01/1970 · Last seen 16/11/5138 · -
interlock relatedRansomware.Live Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 ·
Malware (75)
-
Ixeshe usesFamily The MITRE Corporation Confidence 100
[Ixeshe](https://attack.mitre.org/software/S0015) is a malware family that has been used since at least 2009 against targets in East Asia. (Citation: Moran 2013)
First seen 01/01/1970 · Last seen 16/11/5138 · -
BURNTBATTER usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
BitPaymer usesFamily The MITRE Corporation Confidence 100
[BitPaymer](https://attack.mitre.org/software/S0570) is a ransomware variant first observed in August 2017 targeting hospitals in the U.K. [BitPaymer](https://attack.mitre.org/software/S0570) uses a unique encryption key, ransom note, and contact information for each…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Comnie usesFamily The MITRE Corporation Confidence 100
[Comnie](https://attack.mitre.org/software/S0244) is a remote backdoor which has been used in attacks in East Asia. (Citation: Palo Alto Comnie)
First seen 01/01/1970 · Last seen 16/11/5138 · -
LameHug usesAlienVault Confidence 100
[LAMEHUG](https://attack.mitre.org/software/S9035) is Python-based information stealer first identified in July 2025 by Ukraine's Computer Emergency Response Team (CERT-UA) in phishing emails targeting Ukrainian government officials. [LAMEHUG](https://attack.mitre.org/software/S9035) is the first…
First seen 01/01/1970 · Last seen 16/11/5138 · -
CRYPTBASE.dll usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Hazard Token Grabber usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Rakshasa usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
ShadowPad - S0596 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
TinyTurla - S0668 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Tailscale usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
RainyDay usesFamily The MITRE Corporation Confidence 100
[RainyDay](https://attack.mitre.org/software/S0629) is a backdoor tool that has been used by [Naikon](https://attack.mitre.org/groups/G0019) since at least 2020.(Citation: Bitdefender Naikon April 2021)
First seen 01/01/1970 · Last seen 16/11/5138 ·
Reports (14)
-
AlienVault Confidence 100 18 MITREs 3 IOCs 1 APT
-
AlienVault Confidence 100 20 MITREs 3 IOCs 3 Observables 1 APT
-
AlienVault Confidence 100 1 CVE 20 MITREs 1 IOC 1 Observable
-
20 MITREs 2 Malwares 16 Observables
-
AlienVault Confidence 100 20 MITREs 1 Malware 3 IOCs 3 Observables
-
3 MITREs 23 Observables 1 APT
-
1 CVE 12 MITREs 1 Malware 4 Observables
-
18 MITREs 8 Malwares 12 Observables 1 APT
-
7 MITREs 2 Malwares 45 Observables
-
19 MITREs 1 Malware 6 Observables
-
16 MITREs 1 Malware 12 Observables 1 APT
-
20 MITREs 2 Malwares 33 Observables 1 APT
Vulnerabilities (CVE) (12)
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Progress Telerik UI for ASP.NET AJAX contains a deserialization of untrusted data vulnerability through RadAsyncUpload which leads to code execution on the …
- Published
- 03/11/2021
- Modified
- 20/12/2025
Improper limitation of a pathname to a restricted directory vulnerability in Samsung MagicINFO 9 Server version before 21.1052 allows attackers to write …
- Attack vector
- Network
- Published
- 22/05/2025
- Modified
- 21/12/2025
Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via …
- Published
- 07/04/2023
- Modified
- 21/12/2025
targets
Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a …
- Published
- 07/04/2023
- Modified
- 21/12/2025
Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command …
- Published
- 07/04/2023
- Modified
- 21/12/2025
Wing FTP Server contains an improper neutralization of null byte or NUL character vulnerability that can allow injection of arbitrary Lua code …
- Attack vector
- Network
- Published
- 14/07/2025
- Modified
- 16/03/2026
JetBrains TeamCity contains an authentication bypass vulnerability that allows for remote code execution on TeamCity Server.
- Attack vector
- Network
- Published
- 04/10/2023
- Modified
- 29/05/2026
SAP NetWeaver Visual Composer Metadata Uploader is not protected with a proper authorization, allowing unauthenticated agent to upload potentially malicious executable binaries …
- Attack vector
- Network
- Published
- 29/04/2025
- Modified
- 21/12/2025
Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.
- Attack vector
- Network
- Published
- 17/10/2024
- Modified
- 21/12/2025
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Campaign (1)
-
Operation CuckooBees uses
Tool (2)
-
Net usesThe MITRE Corporation Confidence 100
The [Net](https://attack.mitre.org/software/S0039) utility is a component of the Windows operating system. It is used in command-line operations for control of users, groups, services, and network connections. (Citation: Microsoft…
-
PoshC2 usesThe MITRE Corporation Confidence 100
[PoshC2](https://attack.mitre.org/software/S0378) is an open source remote administration and post-exploitation framework that is publicly available on GitHub. The server-side components of the tool are primarily written in Python, while…