Real-world descriptions of how a group, tool or campaign used a technique.
268 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareLightSpy | If sent the command `16002`, LightSpy uses the `NSWorkspace runningApplications()` method to collect the process ID, path to the executable, bundle information, and the filename of the executable for all running applications. |
| T1057 Process Discovery |
MalwareHELLOKITTY | HELLOKITTY can search for specific processes to terminate. |
| T1057 Process Discovery |
MalwareDarkTortilla | DarkTortilla can enumerate a list of running processes on a compromised system. |
| T1057 Process Discovery |
MalwareROKRAT | ROKRAT can list the current running processes on the system. |
| T1057 Process Discovery |
MalwareBabuk | Babuk has the ability to check running processes on a targeted system. |
| T1057 Process Discovery |
MalwareJavali | Javali can monitor processes for open browsers and custom banking applications. |
| T1057 Process Discovery |
MalwareBBSRAT | BBSRAT can list running processes. |
| T1057 Process Discovery |
MalwarePlugX | PlugX has a module to list the processes running on a machine. |
| T1057 Process Discovery |
MalwareBisonal | Bisonal can obtain a list of running processes on the victim’s machine. |
| T1057 Process Discovery |
MalwareDustySky | DustySky collects information about running processes from victims. |
| T1057 Process Discovery |
MalwareRemsec | Remsec can obtain a process list from the victim. |
| T1057 Process Discovery |
MalwareIndustroyer2 | Industroyer2 has the ability to cyclically enumerate running processes such as PServiceControl.exe, PService_PDD.exe, and other targets supplied through a hardcoded configuration. |
| T1057 Process Discovery |
MalwareSykipot | Sykipot may gather a list of running processes by running |
| T1057 Process Discovery |
MalwareEpic | Epic uses the |
| T1057 Process Discovery |
MalwareCuba | Cuba can enumerate processes running on a victim's machine. |
| T1057 Process Discovery |
MalwareClambling | Clambling can enumerate processes on a targeted system. |
| T1057 Process Discovery |
MalwarePureCrypter | PureCrypter can enumerate processes on compromised hosts. |
| T1057 Process Discovery |
MalwareAkira | Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items. |
| T1057 Process Discovery |
MalwareDarkGate | DarkGate performs various checks for running processes, including security software by looking for hard-coded process name values. |
| T1057 Process Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can identify and terminate specific services. |
| T1057 Process Discovery |
MalwareSVCReady | SVCReady can collect a list of running processes from an infected host. |
| T1057 Process Discovery |
MalwareThiefQuest | ThiefQuest obtains a list of running processes using the function |
| T1057 Process Discovery |
MalwareFoggyWeb | FoggyWeb's loader can enumerate all Common Language Runtimes (CLRs) and running Application Domains in the compromised AD FS server's |
| T1057 Process Discovery |
MalwareCarbanak | Carbanak lists running processes. |
| T1057 Process Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can monitor processes. |
| T1057 Process Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can gather a list of processes running on the machine. |
| T1057 Process Discovery |
MalwareElise | Elise enumerates processes via the |
| T1057 Process Discovery |
MalwareUSBferry | USBferry can use |
| T1057 Process Discovery |
MalwareTSCookie | TSCookie has the ability to list processes on the infected host. |
| T1057 Process Discovery |
MalwareLatrodectus | Latrodectus can enumerate running processes including process grandchildren on targeted hosts. |
| T1057 Process Discovery |
MalwareSaint Bot | Saint Bot has enumerated running processes on a compromised host to determine if it is running under the process name `dfrgui.exe`. |
| T1057 Process Discovery |
MalwareLODEINFO | LODEINFO can kill a process using specific process ID. |
| T1057 Process Discovery |
MalwareCharmPower | CharmPower has the ability to list running processes through the use of `tasklist`. |
| T1057 Process Discovery |
MalwareMuddyViper | MuddyViper has the ability to collect running processes. |
| T1057 Process Discovery |
MalwareBundlore | Bundlore has used the |
| T1057 Process Discovery |
MalwareP8RAT | P8RAT can check for specific processes associated with virtual environments. |
| T1057 Process Discovery |
MalwareSagerunex | Sagerunex identifies the `explorer.exe` process on the executing system. |
| T1057 Process Discovery |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can execute |
| T1057 Process Discovery |
MalwareLP-Notes | LP-Notes has searched for the process taskhostw.exe. |
| T1057 Process Discovery |
MalwareRoyal | Royal can use `GetCurrentProcess` to enumerate processes. |
| T1057 Process Discovery |
MalwareUroburos | Uroburos can use its `Process List` command to enumerate processes on compromised hosts. |
| T1057 Process Discovery |
MalwareMetamorfo | Metamorfo has performed process name checks and has monitored applications. |
| T1057 Process Discovery |
MalwareEmbargo | Embargo has utilized MS4Killer to detect running processes on the victim device. Embargo has also captured a snapshot of active running processes using the Windows API `CreateToolHelp32Snapshot()`. |
| T1057 Process Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can use Tasklist to collect a list of running tasks. |
| T1057 Process Discovery |
MalwarePipeMon | PipeMon can iterate over the running processes to find a suitable injection target. |
| T1057 Process Discovery |
MalwareKONNI | KONNI has used the command |
| T1057 Process Discovery |
Malwaregh0st RAT | gh0st RAT has the capability to list processes. |
| T1057 Process Discovery |
MalwareJHUHUGIT | JHUHUGIT obtains a list of running processes on the victim. |
| T1057 Process Discovery |
MalwareBLUELIGHT | BLUELIGHT can collect process filenames and SID authority level. |
| T1057 Process Discovery |
Malwaredown_new | down_new has the ability to list running processes on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.