ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

4628 examples

TechniqueUsed byProcedure example
T1056.001
Keylogging
GroupTonto Team

Tonto Team has used keylogging tools in their operations.

T1056.001
Keylogging
GroupLazarus Group

Lazarus Group malware KiloAlfa contains keylogging functionality.

T1056.001
Keylogging
GroupFIN4

FIN4 has captured credentials via fake Outlook Web App (OWA) login pages and has also used a .NET based keylogger.

T1056.001
Keylogging
GroupSowbug

Sowbug has used keylogging tools.

T1056.001
Keylogging
GroupHEXANE

HEXANE has used a PowerShell-based keylogger named `kl.ps1`.

T1056.001
Keylogging
GroupPLATINUM

PLATINUM has used several different keyloggers.

T1056.001
Keylogging
GroupMagic Hound

Magic Hound malware is capable of keylogging.

T1056.001
Keylogging
GroupAjax Security Team

Ajax Security Team has used CWoolger and MPK, custom-developed malware, which recorded all keystrokes on an infected system.

T1056.001
Keylogging
GroupThreat Group-3390

Threat Group-3390 actors installed a credential logger on Microsoft Exchange servers. Threat Group-3390 also leveraged the reconnaissance framework, ScanBox, to capture keystrokes.

T1056.001
Keylogging
GroupFIN13

FIN13 has logged the keystrokes of victims to escalate privileges.

T1056.002
GUI Input Capture
GroupRedCurl

RedCurl prompts the user for credentials through a Microsoft Outlook pop-up.

T1056.002
GUI Input Capture
GroupFIN4

FIN4 has presented victims with spoofed Windows Authentication prompts to collect their credentials.

T1056.003
Web Portal Capture
GroupKimsuky

Kimsuky has collected credentials from a fake Google account login page.

T1056.003
Web Portal Capture
GroupWinter Vivern

Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information.

T1056.004
Credential API Hooking
GroupPLATINUM

PLATINUM is capable of using Windows hook interfaces for information gathering such as credential access.

T1057
Process Discovery
GroupAPT38

APT38 leveraged Sysmon to understand the processes, services in the organization.

T1057
Process Discovery
GroupAPT3

APT3 has a tool that can list out currently running processes.

T1057
Process Discovery
GroupKimsuky

Kimsuky can gather a list of all processes running on a victim's machine. Kimsuky has also obtained running processes on the victim device utilizing PowerShell cmdlet `Get-Process`.

T1057
Process Discovery
GroupVolt Typhoon

Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist.

T1057
Process Discovery
GroupHAFNIUM

HAFNIUM has used `tasklist` to enumerate processes.

T1057
Process Discovery
GroupMuddyWater

MuddyWater has used malware to obtain a list of running processes on the system.

T1057
Process Discovery
GroupGamaredon Group

Gamaredon Group has used tools to enumerate processes on target hosts including Process Explorer.

T1057
Process Discovery
GroupTeamTNT

TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools.

T1057
Process Discovery
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery.

T1057
Process Discovery
GroupAndariel

Andariel has used tasklist to enumerate processes and find a specific string.

T1057
Process Discovery
GroupSidewinder

Sidewinder has used tools to identify running processes on the victim's machine.

T1057
Process Discovery
GroupMustang Panda

Mustang Panda has used tasklist /v to determine active process information. Mustang Panda has also used TONESHELL malware to check the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler.

T1057
Process Discovery
GroupRocke

Rocke can detect a running process's PID on the infected machine.

T1057
Process Discovery
GroupUNC3886

UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host.

T1057
Process Discovery
GroupAPT37

APT37's Freenki malware lists running processes using the Microsoft Windows API.

T1057
Process Discovery
GroupOilRig

OilRig has run tasklist on a victim's machine and used infostealers to capture processes.

T1057
Process Discovery
GroupHigaisa

Higaisa’s shellcode attempted to find the process ID of the current process.

T1057
Process Discovery
GroupTropic Trooper

Tropic Trooper is capable of enumerating the running processes on the system using pslist.

T1057
Process Discovery
GroupKe3chang

Ke3chang performs process discovery using tasklist commands.

T1057
Process Discovery
GroupAPT1

APT1 gathered a list of running processes on the system using tasklist /v.

T1057
Process Discovery
GroupTurla

Turla surveys a system upon check-in to discover running processes using the tasklist /v command. Turla RPC backdoors have also enumerated processes associated with specific open ports or named pipes.

T1057
Process Discovery
GroupStorm-0501

Storm-0501 has discovered running processes through `tasklist.exe`.

T1057
Process Discovery
GroupPoseidon Group

After compromising a victim, Poseidon Group lists all running processes.

T1057
Process Discovery
GroupStealth Falcon

Stealth Falcon malware gathers a list of running processes.

T1057
Process Discovery
GroupChimera

Chimera has used tasklist to enumerate processes.

T1057
Process Discovery
GroupMirrorFace

MirrorFace has used Tasklist on compromised hosts for discovery.

T1057
Process Discovery
GroupMedusa Group

Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094.

T1057
Process Discovery
GroupDarkhotel

Darkhotel malware can collect a list of running processes on a system.

T1057
Process Discovery
GroupDeep Panda

Deep Panda uses the Microsoft Tasklist utility to list processes running on systems.

T1057
Process Discovery
GroupWindshift

Windshift has used malware to enumerate active processes.

T1057
Process Discovery
GroupToddyCat

ToddyCat has run `cmd /c start /b tasklist` to enumerate processes.

T1057
Process Discovery
GroupAPT28

An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions.

T1057
Process Discovery
GroupAPT5

APT5 has used Windows-based utilities to carry out tasks including tasklist.exe.

T1057
Process Discovery
GroupWinnti Group

Winnti Group looked for a specific process running on infected servers.

T1057
Process Discovery
GroupLazarus Group

Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.