Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0015 — Detection Strategy for Exclusive Control
DET0015

Detection Strategy for Exclusive Control

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN0045 Analytic 0045
Windows

Detects unusual command executions and service modifications that indicate self-patching or disabling of vulnerable services post-compromise. Defenders should monitor for service stop commands, suspicious process termination, and execution of binaries or scripts aligned with known patching or service management tools outside of expected admin contexts.

WinEventLog:Security EventCode=4688 WinEventLog:Sysmon EventCode=5
[ServiceList] Tunable list of critical or vulnerable services that defenders want to monitor for unexpected disabling.
[TimeWindow] Defines correlation window (e.g., 5–15 minutes) between suspicious command execution and subsequent process termination.
AN0046 Analytic 0046
Linux

Detects adversary attempts to monopolize control of compromised systems by issuing service stop commands, unloading vulnerable modules, or forcefully killing competing processes. Defenders should monitor audit logs and syslog for administrative utilities (systemctl, service, kill) being invoked outside of normal change management.

auditd:SYSCALL execve: Commands like systemctl stop <service>, service <service> stop, or kill -9 <pid> linux:syslog Unexpected termination of daemons or critical services not aligned with admin change tickets
[CriticalProcessList] Defines specific Linux daemons and processes that should not be terminated outside maintenance windows.
[AdminUserContext] Defines expected accounts permitted to execute service stop commands; deviations may be suspicious.
AN0047 Analytic 0047
macOS

Detects unauthorized termination of system daemons or commands issued through launchctl or kill to stop competing services or malware processes. Defenders should monitor unified logs and EDR telemetry for unusual service modifications or terminations.

macos:unifiedlog launchctl unload, kill, or pkill commands affecting daemons or background services macos:osquery process_termination: Unexpected termination of processes tied to vulnerable or high-value services
[ProtectedServiceList] Defines macOS services (e.g., securityd, keychain-related daemons) that should never be disabled.

Detected Techniques

1

Details

MITRE ID
DET0015
STIX ID
x-mitre-detection-strategy--1d8154f6-6890-4441-863f-007600867088
Analytics
3
Techniques Detected
1
By Tactic
Persistence
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.