Files
iimp0ster-detection-chokepo…/chokepoints/defense-evasion/ransomware-service-manipulation.yml
T
imposterandClaude Opus 4.8 95bf405759 feat(ci): chokepoint schema validator + link audit, fix bad data
Adds scripts/validate_schema.py and a validate-data.yml PR gate that
checks every chokepoints/*/*.yml against schema/chokepoint-schema.yml:
required fields, enum values, UUIDv4/ISO-date/MITRE-id formats, tactic
folder consistency, and that referenced Sigma paths exist on disk.
(Replaces the validate_schema.py that cp-drafter referenced but was
never created.) Validator tolerates the authored conventions for
Variations.Status and ExpectedFPRate (leading token + detail).

Fixes surfaced by the validator/link audit:
- 2 invalid Ids regenerated as real UUIDv4 (ransomware-service-
  manipulation, remote-execution-tools)
- 4 dead reference citations repaired (Proofpoint moved URL; Trustwave
  via Wayback; Metasploit psexec -> GitHub docs; BleepingComputer had a
  wrong slug -> correct article)

Adds scripts/check_links.py — advisory external-link sweep (not a CI
gate; external links flake). Buckets BROKEN vs BLOCKED vs OK so API
endpoints and bot-blocked blogs are not mistaken for rot.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-13 10:09:20 -06:00

393 lines
21 KiB
YAML

Name: Ransomware Service Manipulation
Id: cfea844d-1345-4e6c-8821-3a4828f78b82
MitreIds:
- T1562.001
- T1489
Tactics:
- Defense Evasion
- Impact
Techniques:
- 'Impair Defenses: Disable or Modify Tools'
- Service Stop
DetectionPriority: CRITICAL
ThreatPrevalence: HIGH
DetectionDifficulty: LOW
Description: 'Before encrypting files, ransomware operators stop and delete security tools, backup services, and database
engines to maximize impact and prevent recovery. This is the last detectable warning before encryption begins. The chokepoint
is immutable: admin/SYSTEM privileges, service enumeration, and service stop/delete capability are always required regardless
of which ransomware family executes.
'
LastUpdated: '2026-03-07'
Author: '@iimp0ster'
Variations:
- Name: BlackBasta
FirstSeen: '2022'
Status: Legacy
SourceURL: https://reliaquest.com/blog/decline-and-legacy-of-black-basta-whats-next-ransomware-phishing/
NotesShort: Last victim posted January 2025; internal chat logs leaked February 2025; inactive by March 2025. Members migrated
to CACTUS and SafePay
Notes: Targets AV, EDR, Veeam backup, SQL databases; avg TTR 6-12 hours; last victim posted January 2025; internal Matrix
chat logs leaked February 2025; considered inactive by March 2025 after (196k messages) leaked by disgruntled member;
former members migrated to CACTUS and SafePay
VariantId: blackbasta
Command:
Invocation: "sc stop SophosService\nsc stop veeam\nsc stop MSSQLSERVER\nsc stop wbengine\nsc delete SophosService\nsc config veeam start= disabled"
Context: 'Executed via batch script or cmd.exe after gaining SYSTEM via Qakbot/Cobalt Strike. Targets AV, EDR, Veeam backup, SQL databases. Average TTR 6-12 hours from initial access.'
Artifacts:
- 'Sysmon EID 1: sc.exe with stop and security/backup service name'
- 'Sysmon EID 1: sc.exe with delete or config start= disabled'
- 'Windows System EID 7036: Multiple services stopped within 60 seconds'
- 'Windows System EID 7040: Service start type changed to disabled'
ChokepointMapping: 'SYSTEM access → sc.exe enumerates services → bulk sc stop/delete → encryption begins'
- Name: Alphv/BlackCat
FirstSeen: '2021'
Status: Legacy
SourceURL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa23-353a
NotesShort: FBI-disrupted December 2023; resumed operations, attacked Change Healthcare February 2024; exit-scammed affiliates
March 2024 after $22M ransom
Notes: Targets Sophos, Defender, VSS, SQL; cross-platform (Windows and Linux/ESXi); FBI disruption December 2023; exited
via scam March 2024 after $22M Change Healthcare ransom. Leadership withheld affiliate commissions and shut down infrastructure
VariantId: alphv-blackcat
Command:
Invocation: "# Windows Rust binary with embedded service list:\nnet stop \"Sophos Agent\" /y\nnet stop \"vss\" /y\nnet stop \"MSSQL$SQLEXPRESS\" /y\nwmic service where \"name like '%backup%'\" call stopservice"
Context: 'Cross-platform (Windows Rust, Linux C). Windows variant embeds a service kill list. Also uses vssadmin to delete shadow copies. FBI disruption Dec 2023, exit scam March 2024.'
Artifacts:
- 'Sysmon EID 1: net.exe or net1.exe with stop and service name'
- 'Sysmon EID 1: wmic.exe with service and stopservice'
- 'Sysmon EID 1: vssadmin.exe with delete shadows'
- 'Windows System EID 7036: Bulk service stops'
ChokepointMapping: 'SYSTEM → embedded kill list → net stop / wmic stopservice → vssadmin delete shadows → encryption'
- Name: Akira
FirstSeen: '2023'
Status: Active
SourceURL: https://www.cisa.gov/news-events/cybersecurity-advisories/aa24-109a
NotesShort: Prioritizes Defender and backup agents; targets VPN appliances for initial access
Notes: Prioritizes Defender and backup agents; targets VPN appliances for initial access
VariantId: akira
Command:
Invocation: "powershell -Command \"Get-Service -Name *sophos*, *veeam*, *sql*, *backup* | Stop-Service -Force\"\nsc config WinDefend start= disabled\nnet stop WinDefend /y"
Context: 'Prioritizes Defender and backup agents. Initial access via VPN appliances (Cisco, Fortinet). Uses PowerShell for service manipulation alongside sc.exe.'
Artifacts:
- 'Sysmon EID 1: powershell.exe with Stop-Service -Force and wildcard service names'
- 'Sysmon EID 1: sc.exe with config WinDefend start= disabled'
- 'Windows System EID 7036: Defender + backup services stopped'
ChokepointMapping: 'Admin via VPN compromise → PowerShell Get-Service enumeration → Stop-Service -Force → sc config disable'
- Name: Qilin
FirstSeen: '2022'
Status: Active
SourceURL: https://socradar.io/blog/dark-web-profile-qilin-agenda-ransomware/
NotesShort: Rebranded from Agenda; surged with NHS/Synnovis attack June 2024
Notes: Originally tracked as Agenda (Golang); rebranded to Qilin and rewrote in Rust in 2022; fully operational RaaS by
February 2023; targets EDR, Veeam, databases; VMware ESXi variant active; surged to prominence with NHS/Synnovis attack
June 2024
VariantId: qilin
Command:
Invocation: "# Rust binary - service manipulation via Windows API, not sc.exe:\nqilin.exe --kill-services --paths \\\\DC\\SYSVOL\\domain\\scripts\\\n# ESXi variant:\nesxcli vm process list\nesxcli vm process kill --type=force --world-id=<id>"
Context: 'Rewritten in Rust (2022). Uses Windows API directly for service manipulation, reducing sc.exe command-line artifacts. ESXi variant kills VM processes before encrypting VMDK files.'
Artifacts:
- 'Windows System EID 7036: EDR/backup services stopped without sc.exe CLI'
- 'Sysmon EID 1: Qilin binary execution with --kill-services'
- 'ESXi: esxcli process kill events in hostd.log'
ChokepointMapping: 'SYSTEM → Windows API service stop (no sc.exe) → service state changes (EID 7036) → encryption'
- Name: LockBit 3.0
FirstSeen: '2022'
Status: Declining
SourceURL: https://www.trendmicro.com/en_us/research/24/d/operation-cronos-aftermath.html
NotesShort: Operation Cronos seized 28 servers and 1,000+ decryption keys; significantly disrupted
Notes: Comprehensive kill list (50+ services); Group Policy abuse for domain-wide deployment; Operation Cronos (February
2024) seized 28 servers, source code, and 1000+ decryption keys. Significantly reduced operational capacity
VariantId: lockbit-3-0
Command:
Invocation: "# Domain-wide via Group Policy scheduled task:\nschtasks /create /tn \"Windows Update\" /tr \"C:\\windows\\temp\\lockbit.exe\" /sc once /st 00:00 /ru SYSTEM\n# Kill list (50+ services):\nsc stop SophosFileScanner\nsc stop CrowdStrike\nsc stop SentinelAgent\nsc stop veeam\nsc stop MSSQLSERVER\nsc stop wbengine\nsc stop VSS\n# ... 40+ more services\nvssadmin delete shadows /all /quiet\nbcdedit /set {default} recoveryenabled No"
Context: 'Most comprehensive kill list (50+ services). Uses Group Policy for domain-wide deployment. Disables Windows recovery and deletes shadow copies. Operation Cronos (Feb 2024) seized infrastructure.'
Artifacts:
- 'Sysmon EID 1: 50+ sc.exe stop commands in rapid succession'
- 'Sysmon EID 1: vssadmin.exe delete shadows /all /quiet'
- 'Sysmon EID 1: bcdedit.exe /set recoveryenabled No'
- 'Sysmon EID 1: schtasks.exe /create with SYSTEM context'
- 'Windows System EID 7036: 50+ services stopped in under 5 minutes'
- 'Security EID 4698: Scheduled task created across multiple hosts'
ChokepointMapping: 'Domain admin → GPO scheduled task → 50+ sc stop commands → vssadmin + bcdedit → domain-wide encryption'
Prerequisites:
- Admin or SYSTEM privileges already established on target system
- Target security, backup, and database services are running (cannot stop what is not running)
Chokepoints:
- Stage: Service Enumeration
Input: Attacker has SYSTEM privileges on the target system
Invariant: Actor enumerates running services to build the kill list via sc query, Get-Service, wmic, or equivalent
Observable: 'Sysmon EID 1 showing sc.exe query, wmic service get, or Get-Service commands. Multiple service
enumeration commands in rapid succession from the same process or user context.'
WhyCantBypass: Ransomware cannot stop what it cannot find. Service enumeration precedes every observed kill sequence across
all documented families. sc.exe stop and delete require Admin or SYSTEM privileges, so no privilege escalation means immediate
failure before enumeration can complete
LogSources:
- Sysmon Event ID 1 (sc.exe query / wmic service get / Get-Service)
- Windows Security Event ID 4688 (Process Creation)
DetectionTier: Research
SigmaRef: sigma-rules/ransomware-service/research.yml
- Stage: Bulk Service Stop
Input: Service kill list has been built via enumeration
Invariant: Security, backup, and database services are stopped in rapid succession via sc.exe, net stop, taskkill, or WMI
StopService. Multiple services within a short window
Observable: 'Windows System EID 7036 showing multiple security/backup services transitioning to "stopped" state
within 60 seconds. Sysmon EID 1 showing repeated sc stop or net stop commands.'
WhyCantBypass: Files locked by running services cannot be encrypted. Stop must precede encryption in every observed ransomware
family without exception
LogSources:
- Windows System Event ID 7036 (Service State Change - stopped)
- Windows System Event ID 7040 (Service Start Type Changed - disabled)
- Sysmon Event ID 1 (sc.exe / net.exe / taskkill.exe process creation)
DetectionTier: Hunt
SigmaRef: sigma-rules/ransomware-service/hunt.yml
BypassNote: Purpose-built EDR killers (BYOVD drivers, EDRKillShifter) bypass service-stop detection by killing the EDR process
at kernel level. Monitor Sysmon EID 6 for suspicious driver loads immediately before bulk service termination
- Stage: Service Deletion
Input: Target services have been stopped
Invariant: Stopped services are deleted or permanently disabled to prevent automatic restart during the encryption phase
Observable: 'Sysmon EID 1 showing sc.exe delete or sc.exe config start= disabled commands targeting security
and backup services. Registry changes under HKLM\SYSTEM\CurrentControlSet\Services\ confirming service deletion.'
WhyCantBypass: Without deletion, Windows service recovery policies restart stopped services and interfere with encryption.
Deletion is confirmed across all major documented families
LogSources:
- Sysmon Event ID 1 (sc.exe delete / sc.exe config start= disabled)
- Sysmon Event ID 12/13 (Registry key deletion under Services hive)
DetectionTier: Analyst
SigmaRef: sigma-rules/ransomware-service/analyst.yml
EvolutionTimeline:
- Date: 2021-Q2
Event: Database services added to kill lists
Change: SQL Server, MySQL, and PostgreSQL services added to kill lists to release file locks before encryption.
DetectionImpact: Database service monitoring becomes a required detection component
Variants: []
EventType: event
- Date: 2022-Q3
Event: Multi-vendor EDR evasion; kill lists expand to 50+ security products
Change: Kill lists expand to 50+ security products covering all major AV/EDR; threshold-based detection required.
DetectionImpact: Cannot rely on specific product name matches; threshold-based detection required
Variants: []
EventType: event
- Date: 2023-Q4
Event: Backup services prioritized ahead of AV/EDR in kill sequence
Change: Veeam, Acronis, and Windows Backup targeted before AV/EDR; backup service monitoring becomes highest-priority signal.
DetectionImpact: Backup service monitoring becomes highest priority signal
Variants: []
EventType: event
- Date: 2024-Q2
Event: ESXi hypervisor service targeting increases
Change: VM-based service disruption targets vmware-hostd, vpxa, vsanmgmtd; ESXi-specific logging required.
DetectionImpact: ESXi-specific logging (vSphere/vCenter) required; endpoint detection insufficient
Variants: []
EventType: event
- Date: 2024-Q3
Event: Purpose-built EDR killer tooling becomes standard
Change: RansomHub ships EDRKillShifter; DeadLock embeds a weaponized Baidu driver; ~25% of 2024 ransomware attacks incorporated
purpose-built EDR disablement.
DetectionImpact: Cannot rely on known-bad driver hashes alone; monitor for driver load events (Sysmon EID 6) of unsigned
or recently signed drivers immediately before service manipulation
Variants: []
EventType: event
Detections:
- Level: Research
Description: Identify security or backup service state changes (stopped)
LogSources:
- Windows System Event ID 7036 (Service State Change)
- Windows System Event ID 7040 (Service Start Type Change)
Logic: 'EID 7036 Stopped events where Service Name contains sophos, defender, veeam, backup, or antivirus.'
ExpectedFPRate: High
UseCase: Baseline service stop frequency and patterns; identify maintenance windows vs. anomalies
SigmaRule: sigma-rules/ransomware-service/research.yml
- Level: Hunt
Description: Service stop + delete combination for security or backup services in rapid succession
LogSources:
- Windows System Event ID 7036 (Service State Change)
- Windows System Event ID 7040 (Service Start Type Change)
- Sysmon Event ID 1 (Process Creation for sc.exe, net.exe)
Logic: 'sc.exe, net.exe, powershell.exe, or taskkill.exe with CommandLine containing stop AND a service keyword (sophos, defender, veeam, backup, acronis, mssql, mysql), followed within 60 seconds by a delete or disable of the same service via sc.exe. Also fires when 3+ security/backup services stop within 5 minutes from the same process or session.'
ExpectedFPRate: Medium
UseCase: Hunt for ransomware preparation activity; identifies pre-encryption service manipulation
SigmaRule: sigma-rules/ransomware-service/hunt.yml
- Level: Analyst
Description: Network logon + bulk service termination targeting specific security/backup services within a tight window
LogSources:
- Sysmon Event ID 1 (Process Creation)
- Windows Security Event ID 4624 (Logon)
- Windows System Event ID 7036 (Service State)
- Windows System Event ID 7040/7045 (Service Config)
Logic: 'Network logon (4624 LogonType 3) or local admin session running sc.exe/net.exe/taskkill.exe stops 5+ services in 10 minutes targeting security (SophosFileScanner, SAVService, WinDefend, Sense, MsMpEng), backup (Veeam*, VeeamDeploymentService, VSS, wbengine, *acronis*), or database (MSSQL*, SQLWriter, MySQL*, postgresql*), with a service delete attempted within 2 minutes. Weight after-hours activity or unusual source IP.'
ExpectedFPRate: Low
UseCase: SOC alerting; ransomware pre-encryption detection with minimal time to respond
SigmaRule: sigma-rules/ransomware-service/analyst.yml
Intel:
- Name: Kaspersky Common TTPs of Modern Ransomware
Tier: primary
URL: https://media.kasperskycontenthub.com/wp-content/uploads/sites/43/2022/06/23093553/Common-TTPs-of-the-modern-ransomware_low-res.pdf
Description: Comprehensive analysis of service kill lists across major ransomware families
- Name: 'MITRE ATT&CK - T1562.001 Impair Defenses: Disable or Modify Tools'
Tier: primary
URL: https://attack.mitre.org/techniques/T1562/001/
Description: Technique definition, procedure examples, and detection guidance for disabling or modifying security tools
- Name: MITRE ATT&CK - T1489 Service Stop
Tier: primary
URL: https://attack.mitre.org/techniques/T1489/
Description: Technique definition, procedure examples, and detection guidance for stopping services to impair system recovery
RelatedChokepoints:
- remote-execution-tools
- clickfix-techniques
OsintSources:
- Platform: VirusTotal Intelligence
Query: behavior_processes:"sc.exe" tag:ransomware
URL: https://www.virustotal.com/gui/search/behavior_processes%3A%22sc.exe%22%20tag%3Aransomware
Notes: Requires VT Intelligence subscription; pivot to the behavior tab to extract the full service kill list for each ransomware
family and feed service names into the analyst Sigma rule.
- Platform: GitHub Code Search
Query: '"net stop" "sc delete" ransomware path:*.ps1 OR path:*.bat OR path:*.txt'
URL: https://github.com/search?q=%22net+stop%22+%22sc+delete%22+ransomware&type=code
Notes: Finds researcher-published kill lists extracted from decompiled ransomware samples; update the analyst rule's service
name list whenever new families are documented.
- Platform: ANY.RUN Public Feed
URL: https://app.any.run/submissions#status=public&tag=ransomware
Notes: Public ransomware task feed; filter to recent submissions and inspect process trees to see sc.exe and net.exe child
process chains without a local sandbox.
- Platform: Ransomware.live
URL: https://www.ransomware.live
Notes: Real-time ransomware group activity tracker; use to identify currently active families and prioritize hunting for
their service kill lists.
KnownBypasses:
- Bypass: Tamper protection enabled on EDR (requires kernel-level access to disable)
Mitigation: Enable tamper protection on all EDR products; require a signed kernel driver to disable it.
- Bypass: Renaming service before stopping (evades name-based filters)
Mitigation: Allowlist by service binary path rather than service name; alert on service config changes before stop.
- Bypass: Process termination (taskkill /F) instead of service stop
Mitigation: Enable Protected Process Light (PPL) for EDR processes.
- Bypass: WMI or PowerShell-based service stop (evades sc.exe/net.exe process-creation detections)
Mitigation: Monitor WMI activity broadly and restrict WMI remoting via host firewall where not operationally required.
- Bypass: Purpose-built EDR killer tools (EDRKillShifter, weaponized drivers bundled with ransomware)
Mitigation: Enable HVCI and the Microsoft Vulnerable Driver Blocklist; enforce driver signing policy.
RawLogs:
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: sc.exe used to stop a backup service - first service in rapid bulk-stop sequence
MatchedRules:
- Hunt
- Analyst
Sample: 'EventID: 1 (Process Create)
UtcTime: 2024-06-17 22:11:03.447
ProcessId: 5532
Image: C:\Windows\System32\sc.exe
CommandLine: sc stop VeeamBackupSvc
ParentImage: C:\Windows\System32\cmd.exe
'
- Type: Windows Event Log
EventId: 7036
Source: Service Control Manager
Description: Veeam backup service stopped as part of ransomware pre-encryption service kill
MatchedRules:
- Research
- Hunt
- Analyst
Sample: 'EventID: 7036 (The service entered the stopped state)
TimeCreated: 2024-06-17T22:11:03.8834120Z
Channel: System
param1: Veeam Backup Service
param2: stopped
'
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: sc.exe disables service to prevent automatic restart
MatchedRules:
- Hunt
- Analyst
Sample: 'EventID: 1 (Process Create)
UtcTime: 2024-06-17 22:11:04.112
ProcessId: 5540
Image: C:\Windows\System32\sc.exe
CommandLine: sc config VeeamBackupSvc start= disabled
ParentImage: C:\Windows\System32\cmd.exe
'
- Type: Windows Event Log
EventId: 7040
Source: Service Control Manager
Description: Backup service start type changed to disabled - prevents auto-restart
MatchedRules:
- Hunt
- Analyst
Sample: 'EventID: 7040 (The start type of the service was changed)
TimeCreated: 2024-06-17T22:11:04.2201830Z
Channel: System
param1: Veeam Backup Service
param2: disabled
'
- Type: Sysmon
EventId: 1
Source: Microsoft-Windows-Sysmon/Operational
Description: Service deleted to remove backup infrastructure entirely
MatchedRules:
- Hunt
- Analyst
Sample: 'EventID: 1 (Process Create)
UtcTime: 2024-06-17 22:11:07.883
ProcessId: 5548
Image: C:\Windows\System32\sc.exe
CommandLine: sc delete VeeamBackupSvc
ParentImage: C:\Windows\System32\cmd.exe
'
EmulationScript:
File: emulation/ransomware-service-manipulation/emulate.ps1
Language: powershell
Description: Simulates bulk service stop, disable, and delete pattern used by ransomware pre-encryption
SafetyNotes: Requires Administrator. Creates dummy test services. Optionally targets VSS. Lab VM only.
AtomicRef: T1562.001
TheConstant: SYSTEM-level process → service enumeration → bulk service stop/delete → encryption begins
PreventionSummary: >
Ransomware's pre-encryption kill phase relies on a small set of well-known binaries to stop
security and backup services. Application control can block or alert on these tools before
they succeed, buying defenders critical response time before encryption begins.
PreventionOpportunities:
- Category: Endpoint · Application Control
Control: Restrict which processes may invoke service stop/delete commands
Impact: Blocks or delays the pre-encryption kill phase; even a short delay gives defenders
time to intervene before files are encrypted.
MagicSwordFit: MagicSword's Spawn Control rules restrict which parent processes can invoke
service-manipulation binaries (sc.exe, net.exe, taskkill.exe), blocking ransomware kill
scripts without affecting legitimate IT workflows.
MagicSwordTag: lolbas
- Category: Endpoint
Control: Enable Tamper Protection on your EDR/AV and all security tools
Impact: Prevents security services from being stopped even by processes running as SYSTEM,
preserving visibility at the point when it matters most.
- Category: Backup
Control: Enforce immutable, offline-separated backups and restrict vssadmin access
Impact: Preserves recovery options even if ransomware completes its kill list; removes the
business leverage that makes ransom payment attractive.