Real-world descriptions of how a group, tool or campaign used a technique.
268 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate running processes. |
| T1057 Process Discovery |
MalwareBADHATCH | BADHATCH can retrieve a list of running processes from a compromised machine. |
| T1057 Process Discovery |
MalwareMachete | Machete has a component to check for running processes to look for web browsers. |
| T1057 Process Discovery |
MalwareAvenger | Avenger has the ability to use Tasklist to identify running processes. |
| T1057 Process Discovery |
MalwarePUBLOAD | PUBLOAD has used `tasklist` to gather running processes on victim host. PUBLOAD has also leveraged the `OpenEventA` Windows API function to check whether the same process was already running. |
| T1057 Process Discovery |
MalwareSystemBC | SystemBC has the ability to enumerate running processes. |
| T1057 Process Discovery |
MalwareDacls | Dacls can collect data on running and parent processes. |
| T1057 Process Discovery |
MalwareWoody RAT | Woody RAT can call `NtQuerySystemProcessInformation` with `SystemProcessInformation` to enumerate all running processes, including associated information such as PID, parent PID, image name, and owner. |
| T1057 Process Discovery |
MalwareMafalda | Mafalda can enumerate running processes on a machine. |
| T1057 Process Discovery |
MalwareELMER | ELMER is capable of performing process listings. |
| T1057 Process Discovery |
MalwareShrinkLocker | ShrinkLocker checks whether the Bitlocker Drive Encryption Tools service is running. |
| T1057 Process Discovery |
MalwareSombRAT | SombRAT can use the |
| T1057 Process Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can use `ps aux` to enumerate running processes. |
| T1057 Process Discovery |
MalwareMobileOrder | MobileOrder has a command to upload information about all running processes to its C2 server. |
| T1057 Process Discovery |
MalwareInvisiMole | InvisiMole can obtain a list of running processes. |
| T1057 Process Discovery |
MalwareApostle | Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files. |
| T1057 Process Discovery |
MalwareVolgmer | Volgmer can gather a list of processes. |
| T1057 Process Discovery |
MalwareWINERACK | WINERACK can enumerate processes. |
| T1057 Process Discovery |
MalwareFruitFly | FruitFly has the ability to list processes on the system. |
| T1057 Process Discovery |
MalwareSkidmap | Skidmap has monitored critical processes to ensure resiliency. |
| T1057 Process Discovery |
MalwareBonadan | Bonadan can use the |
| T1057 Process Discovery |
MalwareConti | Conti can enumerate through all open processes to search for any that have the string “sql” in their process name. |
| T1057 Process Discovery |
MalwareRaspberry Robin | Raspberry Robin can identify processes running on the victim machine, such as security software, during execution. |
| T1057 Process Discovery |
MalwareMispadu | Mispadu can enumerate the running processes on a compromised host. |
| T1057 Process Discovery |
MalwareMegazord | Megazord can terminate a list of specified services and processes. |
| T1057 Process Discovery |
MalwareDiavol | Diavol has used `CreateToolhelp32Snapshot`, `Process32First`, and `Process32Next` API calls to enumerate the running processes in the system. |
| T1057 Process Discovery |
MalwareDoki | Doki has searched for the current process’s PID. |
| T1057 Process Discovery |
MalwareFysbis | Fysbis can collect information about running processes. |
| T1057 Process Discovery |
MalwareVERMIN | VERMIN can get a list of the processes and running tasks on the system. |
| T1057 Process Discovery |
MalwareUBoatRAT | UBoatRAT can list running processes on the system. |
| T1057 Process Discovery |
MalwareNightdoor | Nightdoor can collect information on installed applications via Windows registry keys, as well as collecting information on running processes. |
| T1057 Process Discovery |
MalwareMarkiRAT | MarkiRAT can search for different processes on a system. |
| T1057 Process Discovery |
MalwarePowerShower | PowerShower has the ability to deploy a reconnaissance module to retrieve a list of the active processes. |
| T1057 Process Discovery |
MalwareKazuar | Kazuar obtains a list of running processes through WMI querying and the |
| T1057 Process Discovery |
MalwareNavRAT | NavRAT uses |
| T1057 Process Discovery |
MalwareDarkComet | DarkComet can list active processes running on the victim’s machine. |
| T1057 Process Discovery |
MalwareNETEAGLE | NETEAGLE can send process listings over the C2 channel. |
| T1057 Process Discovery |
MalwarePOORAIM | POORAIM can enumerate processes. |
| T1057 Process Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can check if a process name contains “creensaver.” |
| T1057 Process Discovery |
MalwareFatDuke | FatDuke can list running processes on the localhost. |
| T1057 Process Discovery |
MalwareLucifer | Lucifer can identify the process that owns remote connections. |
| T1057 Process Discovery |
MalwareBlackEnergy | BlackEnergy has gathered a process list by using Tasklist.exe. |
| T1057 Process Discovery |
MalwareDRATzarus | DRATzarus can enumerate and examine running processes to determine if a debugger is present. |
| T1057 Process Discovery |
MalwareRising Sun | Rising Sun can enumerate all running processes and process information on an infected machine. |
| T1057 Process Discovery |
MalwareObliqueRAT | ObliqueRAT can check for blocklisted process names on a compromised host. |
| T1057 Process Discovery |
MalwareSHOTPUT | SHOTPUT has a command to obtain a process listing. |
| T1057 Process Discovery |
MalwareAvaddon | Avaddon has collected information about running processes. |
| T1057 Process Discovery |
MalwareSocGholish | SocGholish can list processes on targeted hosts. |
| T1057 Process Discovery |
MalwareFlagpro | Flagpro has been used to run the |
| T1057 Process Discovery |
MalwareXAgentOSX | XAgentOSX contains the getProcessList function to run |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.