From 40845ae5ddb6908bcbb3c241837f785a3e7edb2e Mon Sep 17 00:00:00 2001 From: r1ghtstuff <58796595+r1ghtstuff@users.noreply.github.com> Date: Tue, 17 Dec 2019 22:10:44 -0800 Subject: [PATCH] Fix issue #499 for T1007 (#729) --- atomics/T1007/T1007.md | 8 -------- atomics/T1007/T1007.yaml | 9 --------- 2 files changed, 17 deletions(-) diff --git a/atomics/T1007/T1007.md b/atomics/T1007/T1007.md index a5758c52..4821ca27 100644 --- a/atomics/T1007/T1007.md +++ b/atomics/T1007/T1007.md @@ -17,19 +17,11 @@ Identify system services **Supported Platforms:** Windows -#### Inputs -| Name | Description | Type | Default Value | -|------|-------------|------|---------------| -| service_name | Name of service to start stop, query | string | svchost.exe| - #### Run it with `command_prompt`! Elevation Required (e.g. root or admin) ``` tasklist.exe sc query sc query state= all -sc start #{service_name} -sc stop #{service_name} -wmic service where (displayname like "#{service_name}") get name ``` diff --git a/atomics/T1007/T1007.yaml b/atomics/T1007/T1007.yaml index 766e042c..f059817a 100644 --- a/atomics/T1007/T1007.yaml +++ b/atomics/T1007/T1007.yaml @@ -10,12 +10,6 @@ atomic_tests: supported_platforms: - windows - input_arguments: - service_name: - description: Name of service to start stop, query - type: string - default: svchost.exe - executor: name: command_prompt elevation_required: true @@ -23,9 +17,6 @@ atomic_tests: tasklist.exe sc query sc query state= all - sc start #{service_name} - sc stop #{service_name} - wmic service where (displayname like "#{service_name}") get name - name: System Service Discovery - net.exe description: |