Real-world descriptions of how a group, tool or campaign used a technique.
268 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareTrickBot | TrickBot uses module networkDll for process list discovery. |
| T1057 Process Discovery |
MalwarePowerDuke | PowerDuke has a command to list the victim's processes. |
| T1057 Process Discovery |
MalwareEKANS | EKANS looks for processes from a hard-coded list. |
| T1057 Process Discovery |
MalwareNinja | Ninja can enumerate processes on a targeted host. |
| T1057 Process Discovery |
MalwareRCSession | RCSession can identify processes based on PID. |
| T1057 Process Discovery |
MalwareSynAck | SynAck enumerates all running processes. |
| T1057 Process Discovery |
MalwareBumblebee | Bumblebee can identify processes associated with analytical tools. |
| T1057 Process Discovery |
MalwareBRICKSTORM | BRICKSTORM has the ability to check if it is running as an active child process through the detection of a specific environment variable. |
| T1057 Process Discovery |
MalwareProxysvc | Proxysvc lists processes running on the system. |
| T1057 Process Discovery |
MalwareOrz | Orz can gather a process list from the victim. |
| T1057 Process Discovery |
Malwareyty | yty gets an output of running processes using the |
| T1057 Process Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about running processes. |
| T1057 Process Discovery |
MalwareRotaJakiro | RotaJakiro can monitor the `/proc/[PID]` directory of known RotaJakiro processes as a part of its persistence when executing with non-root permissions. If the process is found dead, it resurrects the process. RotaJakiro processes can be matched to an associated Advisory Lock, in the `/proc/locks` folder, to ensure it doesn't spawn more than one process. |
| T1057 Process Discovery |
MalwareAvosLocker | AvosLocker has discovered system processes by calling `RmGetList`. |
| T1057 Process Discovery |
MalwareGet2 | Get2 has the ability to identify running processes on an infected host. |
| T1057 Process Discovery |
MalwarePOWRUNER | POWRUNER may collect process information by running |
| T1057 Process Discovery |
MalwareKOPILUWAK | KOPILUWAK can enumerate current running processes on the targeted machine. |
| T1057 Process Discovery |
MalwarePAKLOG | PAKLOG has detected and logged the full path of processes active in the foreground using Windows API calls. |
| T1057 Process Discovery |
MalwareCOATHANGER | COATHANGER will query running process information to determine subsequent program execution flow. |
| T1057 Process Discovery |
MalwareSardonic | Sardonic has the ability to execute the `tasklist` command. |
| T1057 Process Discovery |
MalwareHALFBAKED | HALFBAKED can obtain information about running processes on the victim. |
| T1057 Process Discovery |
MalwareKEYMARBLE | KEYMARBLE can obtain a list of running processes on the system. |
| T1057 Process Discovery |
MalwareUrsnif | Ursnif has gathered information about running processes. |
| T1057 Process Discovery |
MalwareRansomHub | RansomHub can stop processes associated with files currently in use to maximize the impact of encryption. |
| T1057 Process Discovery |
MalwareZeus Panda | Zeus Panda checks for running processes on the victim’s machine. |
| T1057 Process Discovery |
MalwareGeminiDuke | GeminiDuke collects information on running processes and environment variables from the victim. |
| T1057 Process Discovery |
MalwareHavoc | Havoc can enumerate processes on targeted hosts. |
| T1057 Process Discovery |
MalwareFrameworkPOS | FrameworkPOS can enumerate and exclude selected processes on a compromised host to speed execution of memory scraping. |
| T1057 Process Discovery |
MalwareGravityRAT | GravityRAT lists the running processes on the system. |
| T1057 Process Discovery |
MalwareInvisibleFerret | InvisibleFerret has the capability to query installed programs and running processes. InvisibleFerret has also identified running processes using the Python project “psutil”. |
| T1057 Process Discovery |
MalwareBankshot | Bankshot identifies processes and collects the process ids. |
| T1057 Process Discovery |
MalwareStrongPity | StrongPity can determine if a user is logged in by checking to see if explorer.exe is running. |
| T1057 Process Discovery |
MalwarePLAINTEE | PLAINTEE performs the |
| T1057 Process Discovery |
MalwareWinMM | WinMM sets a WH_CBT Windows hook to collect information on process creation. |
| T1057 Process Discovery |
MalwareNebulae | Nebulae can enumerate processes on a target system. |
| T1057 Process Discovery |
MalwareTONESHELL | TONESHELL has checked the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler. TONESHELL has also searched for running antivirus processes to include ESET’s antivirus associated executables ekrn.exe and egui.exe. |
| T1057 Process Discovery |
MalwareUPSTYLE | UPSTYLE has the ability to read `/proc/self/cmdline` to see if it is running as a monitored process. |
| T1057 Process Discovery |
MalwareKasidet | Kasidet has the ability to search for a given process name in processes currently running in the system. |
| T1057 Process Discovery |
MalwareOceanSalt | OceanSalt can collect the name and ID for every process running on the system. |
| T1057 Process Discovery |
MalwareBrave Prince | Brave Prince lists the running processes. |
| T1057 Process Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates. |
| T1057 Process Discovery |
MalwareRainyDay | RainyDay can enumerate processes on a target system. |
| T1057 Process Discovery |
MalwareAppleSeed | AppleSeed can enumerate the current process on a compromised host. |
| T1057 Process Discovery |
MalwaremacOS.OSAMiner | macOS.OSAMiner has used `ps ax | grep <name> | grep -v grep | ...` and `ps ax | grep -E...` to conduct process discovery. |
| T1057 Process Discovery |
MalwareNETWIRE | NETWIRE can discover processes on compromised hosts. |
| T1057 Process Discovery |
MalwareiKitten | iKitten lists the current processes running. |
| T1057 Process Discovery |
MalwareBad Rabbit | Bad Rabbit can enumerate all running processes to compare hashes. |
| T1057 Process Discovery |
MalwareAria-body | Aria-body has the ability to enumerate loaded modules for a process.. |
| T1057 Process Discovery |
MalwareEmotet | Emotet has been observed enumerating local processes. |
| T1057 Process Discovery |
MalwareCrimson | Crimson contains a command to list processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.