Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0040 ✕
Download CSV Show ATT&CK heatmapA service was disabled Informational 3 variations
A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Impact (TA0040)ATT&CK techniques: Service Stop (T1489)Required data: XDR AgentAttacker's goals: Evade detection by certain programs. Limit the functionality and availability of systems, services, and network resources.Investigative actions: Check if the disabled service could potentially threaten a malicious actor, or if holds a critical role. Investigate the disabling process to understand if it performed other suspicious actions.Variations
A service was disabled without using the ServiceControlManager RPC interface
Informational overridden
A service was disabled abnormally through the registry. This may be performed by malicious actors in an attempt to evade detection or limit functionality. overridden
An injected process performed an uncommon service deactivation
Informational overridden
A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality. overridden
An unsigned process performed an uncommon service deactivation
Low overridden
A service was disabled abnormally. This may be performed by malicious actors in an attempt to evade detection or limit functionality. overridden