ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1057×

268 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareTrickBot

TrickBot uses module networkDll for process list discovery.

T1057
Process Discovery
MalwarePowerDuke

PowerDuke has a command to list the victim's processes.

T1057
Process Discovery
MalwareEKANS

EKANS looks for processes from a hard-coded list.

T1057
Process Discovery
MalwareNinja

Ninja can enumerate processes on a targeted host.

T1057
Process Discovery
MalwareRCSession

RCSession can identify processes based on PID.

T1057
Process Discovery
MalwareSynAck

SynAck enumerates all running processes.

T1057
Process Discovery
MalwareBumblebee

Bumblebee can identify processes associated with analytical tools.

T1057
Process Discovery
MalwareBRICKSTORM

BRICKSTORM has the ability to check if it is running as an active child process through the detection of a specific environment variable.

T1057
Process Discovery
MalwareProxysvc

Proxysvc lists processes running on the system.

T1057
Process Discovery
MalwareOrz

Orz can gather a process list from the victim.

T1057
Process Discovery
Malwareyty

yty gets an output of running processes using the tasklist command.

T1057
Process Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about running processes.

T1057
Process Discovery
MalwareRotaJakiro

RotaJakiro can monitor the `/proc/[PID]` directory of known RotaJakiro processes as a part of its persistence when executing with non-root permissions. If the process is found dead, it resurrects the process. RotaJakiro processes can be matched to an associated Advisory Lock, in the `/proc/locks` folder, to ensure it doesn't spawn more than one process.

T1057
Process Discovery
MalwareAvosLocker

AvosLocker has discovered system processes by calling `RmGetList`.

T1057
Process Discovery
MalwareGet2

Get2 has the ability to identify running processes on an infected host.

T1057
Process Discovery
MalwarePOWRUNER

POWRUNER may collect process information by running tasklist on a victim.

T1057
Process Discovery
MalwareKOPILUWAK

KOPILUWAK can enumerate current running processes on the targeted machine.

T1057
Process Discovery
MalwarePAKLOG

PAKLOG has detected and logged the full path of processes active in the foreground using Windows API calls.

T1057
Process Discovery
MalwareCOATHANGER

COATHANGER will query running process information to determine subsequent program execution flow.

T1057
Process Discovery
MalwareSardonic

Sardonic has the ability to execute the `tasklist` command.

T1057
Process Discovery
MalwareHALFBAKED

HALFBAKED can obtain information about running processes on the victim.

T1057
Process Discovery
MalwareKEYMARBLE

KEYMARBLE can obtain a list of running processes on the system.

T1057
Process Discovery
MalwareUrsnif

Ursnif has gathered information about running processes.

T1057
Process Discovery
MalwareRansomHub

RansomHub can stop processes associated with files currently in use to maximize the impact of encryption.

T1057
Process Discovery
MalwareZeus Panda

Zeus Panda checks for running processes on the victim’s machine.

T1057
Process Discovery
MalwareGeminiDuke

GeminiDuke collects information on running processes and environment variables from the victim.

T1057
Process Discovery
MalwareHavoc

Havoc can enumerate processes on targeted hosts.

T1057
Process Discovery
MalwareFrameworkPOS

FrameworkPOS can enumerate and exclude selected processes on a compromised host to speed execution of memory scraping.

T1057
Process Discovery
MalwareGravityRAT

GravityRAT lists the running processes on the system.

T1057
Process Discovery
MalwareInvisibleFerret

InvisibleFerret has the capability to query installed programs and running processes. InvisibleFerret has also identified running processes using the Python project “psutil”.

T1057
Process Discovery
MalwareBankshot

Bankshot identifies processes and collects the process ids.

T1057
Process Discovery
MalwareStrongPity

StrongPity can determine if a user is logged in by checking to see if explorer.exe is running.

T1057
Process Discovery
MalwarePLAINTEE

PLAINTEE performs the tasklist command to list running processes.

T1057
Process Discovery
MalwareWinMM

WinMM sets a WH_CBT Windows hook to collect information on process creation.

T1057
Process Discovery
MalwareNebulae

Nebulae can enumerate processes on a target system.

T1057
Process Discovery
MalwareTONESHELL

TONESHELL has checked the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler. TONESHELL has also searched for running antivirus processes to include ESET’s antivirus associated executables ekrn.exe and egui.exe.

T1057
Process Discovery
MalwareUPSTYLE

UPSTYLE has the ability to read `/proc/self/cmdline` to see if it is running as a monitored process.

T1057
Process Discovery
MalwareKasidet

Kasidet has the ability to search for a given process name in processes currently running in the system.

T1057
Process Discovery
MalwareOceanSalt

OceanSalt can collect the name and ID for every process running on the system.

T1057
Process Discovery
MalwareBrave Prince

Brave Prince lists the running processes.

T1057
Process Discovery
MalwareMedusa Ransomware

Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates.

T1057
Process Discovery
MalwareRainyDay

RainyDay can enumerate processes on a target system.

T1057
Process Discovery
MalwareAppleSeed

AppleSeed can enumerate the current process on a compromised host.

T1057
Process Discovery
MalwaremacOS.OSAMiner

macOS.OSAMiner has used `ps ax | grep <name> | grep -v grep | ...` and `ps ax | grep -E...` to conduct process discovery.

T1057
Process Discovery
MalwareNETWIRE

NETWIRE can discover processes on compromised hosts.

T1057
Process Discovery
MalwareiKitten

iKitten lists the current processes running.

T1057
Process Discovery
MalwareBad Rabbit

Bad Rabbit can enumerate all running processes to compare hashes.

T1057
Process Discovery
MalwareAria-body

Aria-body has the ability to enumerate loaded modules for a process..

T1057
Process Discovery
MalwareEmotet

Emotet has been observed enumerating local processes.

T1057
Process Discovery
MalwareCrimson

Crimson contains a command to list processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.