Compliance Node Overview
MITRE ATT&CK T1489 (Service Stop) is an Enterprise Impact technique. Adversaries may stop or disable services on a system to render those services unavailable to legitimate users. Stopping critical services or processes can inhibit or stop response to an incident or aid in the adversary's overall objectives to cause damage to the environment. Adversaries may accomplish this by disabling individual services of high importance to an organization, such as MSExchangeIS, which will make Exchange content inaccessible. Affected platforms: Windows, Linux, macOS. MITRE-documented mitigations include M1030 Network Segmentation, M1018 User Account Management, M1060 Out-of-Band Communications Channel, M1024 Restrict Registry Permissions, M1022 Restrict File and Directory Permissions. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, AC-03, AC-04, AC-05, AC-06, CA-07, CM-05, CM-06.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1489/
SHA-256 integrity: e243ee6f0f3dbe8bef24df65d4aa856e83d7b728e156987028225bc8ba9c9a74
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1489: Service Stop (https://attack.mitre.org/techniques/T1489/)
- MITRE ATT&CK Tactic TA0040: Impact (https://attack.mitre.org/tactics/TA0040/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access