Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.001 Keylogging |
GroupTonto Team | Tonto Team has used keylogging tools in their operations. |
| T1056.001 Keylogging |
GroupLazarus Group | Lazarus Group malware KiloAlfa contains keylogging functionality. |
| T1056.001 Keylogging |
GroupFIN4 | FIN4 has captured credentials via fake Outlook Web App (OWA) login pages and has also used a .NET based keylogger. |
| T1056.001 Keylogging |
GroupSowbug | Sowbug has used keylogging tools. |
| T1056.001 Keylogging |
GroupHEXANE | HEXANE has used a PowerShell-based keylogger named `kl.ps1`. |
| T1056.001 Keylogging |
GroupPLATINUM | PLATINUM has used several different keyloggers. |
| T1056.001 Keylogging |
GroupMagic Hound | Magic Hound malware is capable of keylogging. |
| T1056.001 Keylogging |
GroupAjax Security Team | Ajax Security Team has used CWoolger and MPK, custom-developed malware, which recorded all keystrokes on an infected system. |
| T1056.001 Keylogging |
GroupThreat Group-3390 | Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes. |
| T1056.001 Keylogging |
GroupFIN13 | FIN13 has logged the keystrokes of victims to escalate privileges. |
| T1056.002 GUI Input Capture |
GroupRedCurl | RedCurl prompts the user for credentials through a Microsoft Outlook pop-up. |
| T1056.002 GUI Input Capture |
GroupFIN4 | FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials. |
| T1056.003 Web Portal Capture |
GroupKimsuky | Kimsuky has collected credentials from a fake Google account login page. |
| T1056.003 Web Portal Capture |
GroupWinter Vivern | Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information. |
| T1056.004 Credential API Hooking |
GroupPLATINUM | PLATINUM is capable of using Windows hook interfaces for information gathering such as credential access. |
| T1057 Process Discovery |
GroupAPT38 | APT38 leveraged Sysmon to understand the processes, services in the organization. |
| T1057 Process Discovery |
GroupAPT3 | APT3 has a tool that can list out currently running processes. |
| T1057 Process Discovery |
GroupKimsuky | Kimsuky can gather a list of all processes running on a victim's machine. Kimsuky has also obtained running processes on the victim device utilizing PowerShell cmdlet `Get-Process`. |
| T1057 Process Discovery |
GroupVolt Typhoon | Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist. |
| T1057 Process Discovery |
GroupHAFNIUM | HAFNIUM has used `tasklist` to enumerate processes. |
| T1057 Process Discovery |
GroupMuddyWater | MuddyWater has used malware to obtain a list of running processes on the system. |
| T1057 Process Discovery |
GroupGamaredon Group | Gamaredon Group has used tools to enumerate processes on target hosts including Process Explorer. |
| T1057 Process Discovery |
GroupTeamTNT | TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools. |
| T1057 Process Discovery |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery. |
| T1057 Process Discovery |
GroupAndariel | Andariel has used |
| T1057 Process Discovery |
GroupSidewinder | Sidewinder has used tools to identify running processes on the victim's machine. |
| T1057 Process Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1057 Process Discovery |
GroupRocke | Rocke can detect a running process's PID on the infected machine. |
| T1057 Process Discovery |
GroupUNC3886 | UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host. |
| T1057 Process Discovery |
GroupAPT37 | APT37's Freenki malware lists running processes using the Microsoft Windows API. |
| T1057 Process Discovery |
GroupOilRig | OilRig has run |
| T1057 Process Discovery |
GroupHigaisa | Higaisa’s shellcode attempted to find the process ID of the current process. |
| T1057 Process Discovery |
GroupTropic Trooper | Tropic Trooper is capable of enumerating the running processes on the system using |
| T1057 Process Discovery |
GroupKe3chang | Ke3chang performs process discovery using |
| T1057 Process Discovery |
GroupAPT1 | APT1 gathered a list of running processes on the system using |
| T1057 Process Discovery |
GroupTurla | Turla surveys a system upon check-in to discover running processes using the |
| T1057 Process Discovery |
GroupStorm-0501 | Storm-0501 has discovered running processes through `tasklist.exe`. |
| T1057 Process Discovery |
GroupPoseidon Group | After compromising a victim, Poseidon Group lists all running processes. |
| T1057 Process Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers a list of running processes. |
| T1057 Process Discovery |
GroupChimera | Chimera has used |
| T1057 Process Discovery |
GroupMirrorFace | MirrorFace has used Tasklist on compromised hosts for discovery. |
| T1057 Process Discovery |
GroupMedusa Group | Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094. |
| T1057 Process Discovery |
GroupDarkhotel | Darkhotel malware can collect a list of running processes on a system. |
| T1057 Process Discovery |
GroupDeep Panda | Deep Panda uses the Microsoft Tasklist utility to list processes running on systems. |
| T1057 Process Discovery |
GroupWindshift | Windshift has used malware to enumerate active processes. |
| T1057 Process Discovery |
GroupToddyCat | ToddyCat has run `cmd /c start /b tasklist` to enumerate processes. |
| T1057 Process Discovery |
GroupAPT28 | An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions. |
| T1057 Process Discovery |
GroupAPT5 | APT5 has used Windows-based utilities to carry out tasks including tasklist.exe. |
| T1057 Process Discovery |
GroupWinnti Group | Winnti Group looked for a specific process running on infected servers. |
| T1057 Process Discovery |
GroupLazarus Group | Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.