ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1057×

268 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareLightSpy

If sent the command `16002`, LightSpy uses the `NSWorkspace runningApplications()` method to collect the process ID, path to the executable, bundle information, and the filename of the executable for all running applications.

T1057
Process Discovery
MalwareHELLOKITTY

HELLOKITTY can search for specific processes to terminate.

T1057
Process Discovery
MalwareDarkTortilla

DarkTortilla can enumerate a list of running processes on a compromised system.

T1057
Process Discovery
MalwareROKRAT

ROKRAT can list the current running processes on the system.

T1057
Process Discovery
MalwareBabuk

Babuk has the ability to check running processes on a targeted system.

T1057
Process Discovery
MalwareJavali

Javali can monitor processes for open browsers and custom banking applications.

T1057
Process Discovery
MalwareBBSRAT

BBSRAT can list running processes.

T1057
Process Discovery
MalwarePlugX

PlugX has a module to list the processes running on a machine.

T1057
Process Discovery
MalwareBisonal

Bisonal can obtain a list of running processes on the victim’s machine.

T1057
Process Discovery
MalwareDustySky

DustySky collects information about running processes from victims.

T1057
Process Discovery
MalwareRemsec

Remsec can obtain a process list from the victim.

T1057
Process Discovery
MalwareIndustroyer2

Industroyer2 has the ability to cyclically enumerate running processes such as PServiceControl.exe, PService_PDD.exe, and other targets supplied through a hardcoded configuration.

T1057
Process Discovery
MalwareSykipot

Sykipot may gather a list of running processes by running tasklist /v.

T1057
Process Discovery
MalwareEpic

Epic uses the tasklist /v command to obtain a list of processes.

T1057
Process Discovery
MalwareCuba

Cuba can enumerate processes running on a victim's machine.

T1057
Process Discovery
MalwareClambling

Clambling can enumerate processes on a targeted system.

T1057
Process Discovery
MalwarePureCrypter

PureCrypter can enumerate processes on compromised hosts.

T1057
Process Discovery
MalwareAkira

Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items.

T1057
Process Discovery
MalwareDarkGate

DarkGate performs various checks for running processes, including security software by looking for hard-coded process name values.

T1057
Process Discovery
MalwareLockBit 3.0

LockBit 3.0 can identify and terminate specific services.

T1057
Process Discovery
MalwareSVCReady

SVCReady can collect a list of running processes from an infected host.

T1057
Process Discovery
MalwareThiefQuest

ThiefQuest obtains a list of running processes using the function kill_unwanted.

T1057
Process Discovery
MalwareFoggyWeb

FoggyWeb's loader can enumerate all Common Language Runtimes (CLRs) and running Application Domains in the compromised AD FS server's Microsoft.IdentityServer.ServiceHost.exe process.

T1057
Process Discovery
MalwareCarbanak

Carbanak lists running processes.

T1057
Process Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can monitor processes.

T1057
Process Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can gather a list of processes running on the machine.

T1057
Process Discovery
MalwareElise

Elise enumerates processes via the tasklist command.

T1057
Process Discovery
MalwareUSBferry

USBferry can use tasklist to gather information about the process running on the infected system.

T1057
Process Discovery
MalwareTSCookie

TSCookie has the ability to list processes on the infected host.

T1057
Process Discovery
MalwareLatrodectus

Latrodectus can enumerate running processes including process grandchildren on targeted hosts.

T1057
Process Discovery
MalwareSaint Bot

Saint Bot has enumerated running processes on a compromised host to determine if it is running under the process name `dfrgui.exe`.

T1057
Process Discovery
MalwareLODEINFO

LODEINFO can kill a process using specific process ID.

T1057
Process Discovery
MalwareCharmPower

CharmPower has the ability to list running processes through the use of `tasklist`.

T1057
Process Discovery
MalwareMuddyViper

MuddyViper has the ability to collect running processes.

T1057
Process Discovery
MalwareBundlore

Bundlore has used the ps command to list processes.

T1057
Process Discovery
MalwareP8RAT

P8RAT can check for specific processes associated with virtual environments.

T1057
Process Discovery
MalwareSagerunex

Sagerunex identifies the `explorer.exe` process on the executing system.

T1057
Process Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can execute ProcessList for process discovery.

T1057
Process Discovery
MalwareLP-Notes

LP-Notes has searched for the process taskhostw.exe.

T1057
Process Discovery
MalwareRoyal

Royal can use `GetCurrentProcess` to enumerate processes.

T1057
Process Discovery
MalwareUroburos

Uroburos can use its `Process List` command to enumerate processes on compromised hosts.

T1057
Process Discovery
MalwareMetamorfo

Metamorfo has performed process name checks and has monitored applications.

T1057
Process Discovery
MalwareEmbargo

Embargo has utilized MS4Killer to detect running processes on the victim device. Embargo has also captured a snapshot of active running processes using the Windows API `CreateToolHelp32Snapshot()`.

T1057
Process Discovery
MalwareTrojan.Karagany

Trojan.Karagany can use Tasklist to collect a list of running tasks.

T1057
Process Discovery
MalwarePipeMon

PipeMon can iterate over the running processes to find a suitable injection target.

T1057
Process Discovery
MalwareKONNI

KONNI has used the command cmd /c tasklist to get a snapshot of the current processes on the target machine.

T1057
Process Discovery
Malwaregh0st RAT

gh0st RAT has the capability to list processes.

T1057
Process Discovery
MalwareJHUHUGIT

JHUHUGIT obtains a list of running processes on the victim.

T1057
Process Discovery
MalwareBLUELIGHT

BLUELIGHT can collect process filenames and SID authority level.

T1057
Process Discovery
Malwaredown_new

down_new has the ability to list running processes on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.