ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1057×

268 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate running processes.

T1057
Process Discovery
MalwareBADHATCH

BADHATCH can retrieve a list of running processes from a compromised machine.

T1057
Process Discovery
MalwareMachete

Machete has a component to check for running processes to look for web browsers.

T1057
Process Discovery
MalwareAvenger

Avenger has the ability to use Tasklist to identify running processes.

T1057
Process Discovery
MalwarePUBLOAD

PUBLOAD has used `tasklist` to gather running processes on victim host. PUBLOAD has also leveraged the `OpenEventA` Windows API function to check whether the same process was already running.

T1057
Process Discovery
MalwareSystemBC

SystemBC has the ability to enumerate running processes.

T1057
Process Discovery
MalwareDacls

Dacls can collect data on running and parent processes.

T1057
Process Discovery
MalwareWoody RAT

Woody RAT can call `NtQuerySystemProcessInformation` with `SystemProcessInformation` to enumerate all running processes, including associated information such as PID, parent PID, image name, and owner.

T1057
Process Discovery
MalwareMafalda

Mafalda can enumerate running processes on a machine.

T1057
Process Discovery
MalwareELMER

ELMER is capable of performing process listings.

T1057
Process Discovery
MalwareShrinkLocker

ShrinkLocker checks whether the Bitlocker Drive Encryption Tools service is running.

T1057
Process Discovery
MalwareSombRAT

SombRAT can use the getprocesslist command to enumerate processes on a compromised host.

T1057
Process Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can use `ps aux` to enumerate running processes.

T1057
Process Discovery
MalwareMobileOrder

MobileOrder has a command to upload information about all running processes to its C2 server.

T1057
Process Discovery
MalwareInvisiMole

InvisiMole can obtain a list of running processes.

T1057
Process Discovery
MalwareApostle

Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files.

T1057
Process Discovery
MalwareVolgmer

Volgmer can gather a list of processes.

T1057
Process Discovery
MalwareWINERACK

WINERACK can enumerate processes.

T1057
Process Discovery
MalwareFruitFly

FruitFly has the ability to list processes on the system.

T1057
Process Discovery
MalwareSkidmap

Skidmap has monitored critical processes to ensure resiliency.

T1057
Process Discovery
MalwareBonadan

Bonadan can use the ps command to discover other cryptocurrency miners active on the system.

T1057
Process Discovery
MalwareConti

Conti can enumerate through all open processes to search for any that have the string “sql” in their process name.

T1057
Process Discovery
MalwareRaspberry Robin

Raspberry Robin can identify processes running on the victim machine, such as security software, during execution.

T1057
Process Discovery
MalwareMispadu

Mispadu can enumerate the running processes on a compromised host.

T1057
Process Discovery
MalwareMegazord

Megazord can terminate a list of specified services and processes.

T1057
Process Discovery
MalwareDiavol

Diavol has used `CreateToolhelp32Snapshot`, `Process32First`, and `Process32Next` API calls to enumerate the running processes in the system.

T1057
Process Discovery
MalwareDoki

Doki has searched for the current process’s PID.

T1057
Process Discovery
MalwareFysbis

Fysbis can collect information about running processes.

T1057
Process Discovery
MalwareVERMIN

VERMIN can get a list of the processes and running tasks on the system.

T1057
Process Discovery
MalwareUBoatRAT

UBoatRAT can list running processes on the system.

T1057
Process Discovery
MalwareNightdoor

Nightdoor can collect information on installed applications via Windows registry keys, as well as collecting information on running processes.

T1057
Process Discovery
MalwareMarkiRAT

MarkiRAT can search for different processes on a system.

T1057
Process Discovery
MalwarePowerShower

PowerShower has the ability to deploy a reconnaissance module to retrieve a list of the active processes.

T1057
Process Discovery
MalwareKazuar

Kazuar obtains a list of running processes through WMI querying and the ps command.

T1057
Process Discovery
MalwareNavRAT

NavRAT uses tasklist /v to check running processes.

T1057
Process Discovery
MalwareDarkComet

DarkComet can list active processes running on the victim’s machine.

T1057
Process Discovery
MalwareNETEAGLE

NETEAGLE can send process listings over the C2 channel.

T1057
Process Discovery
MalwarePOORAIM

POORAIM can enumerate processes.

T1057
Process Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can check if a process name contains “creensaver.”

T1057
Process Discovery
MalwareFatDuke

FatDuke can list running processes on the localhost.

T1057
Process Discovery
MalwareLucifer

Lucifer can identify the process that owns remote connections.

T1057
Process Discovery
MalwareBlackEnergy

BlackEnergy has gathered a process list by using Tasklist.exe.

T1057
Process Discovery
MalwareDRATzarus

DRATzarus can enumerate and examine running processes to determine if a debugger is present.

T1057
Process Discovery
MalwareRising Sun

Rising Sun can enumerate all running processes and process information on an infected machine.

T1057
Process Discovery
MalwareObliqueRAT

ObliqueRAT can check for blocklisted process names on a compromised host.

T1057
Process Discovery
MalwareSHOTPUT

SHOTPUT has a command to obtain a process listing.

T1057
Process Discovery
MalwareAvaddon

Avaddon has collected information about running processes.

T1057
Process Discovery
MalwareSocGholish

SocGholish can list processes on targeted hosts.

T1057
Process Discovery
MalwareFlagpro

Flagpro has been used to run the tasklist command on a compromised system.

T1057
Process Discovery
MalwareXAgentOSX

XAgentOSX contains the getProcessList function to run ps aux to get running processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.