ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1057×

268 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareIxeshe

Ixeshe can list running processes.

T1057
Process Discovery
Malware4H RAT

4H RAT has the capability to obtain a listing of running processes (including loaded modules).

T1057
Process Discovery
MalwareRogueRobin

RogueRobin checks the running processes for evidence it may be running in a sandbox environment. It specifically enumerates processes for Wireshark and Sysinternals.

T1057
Process Discovery
MalwareStreamEx

StreamEx has the ability to enumerate processes.

T1057
Process Discovery
MalwareNightClub

NightClub has the ability to use `GetWindowThreadProcessId` to identify the process behind a specified window.

T1057
Process Discovery
MalwareSDBbot

SDBbot can enumerate a list of running processes on a compromised machine.

T1057
Process Discovery
MalwareMosquito

Mosquito runs tasklist to obtain running processes.

T1057
Process Discovery
MalwareRTM

RTM can obtain information about process integrity levels.

T1057
Process Discovery
MalwareDerusbi

Derusbi collects current and parent process IDs.

T1057
Process Discovery
MalwareSodaMaster

SodaMaster can search a list of running processes.

T1057
Process Discovery
MalwareGrandoreiro

Grandoreiro can identify installed security tools based on process names.

T1057
Process Discovery
MalwareZxxZ

ZxxZ has created a snapshot of running processes using `CreateToolhelp32Snapshot`.

T1057
Process Discovery
MalwareBazar

Bazar can identity the current process on a compromised host.

T1057
Process Discovery
MalwareRATANKBA

RATANKBA lists the system’s processes.

T1057
Process Discovery
MalwareMoonWind

MoonWind has a command to return a list of running processes.

T1057
Process Discovery
MalwareHiddenFace

HiddenFace can check running processes against a list of blocklisted applications.

T1057
Process Discovery
MalwareRyuk

Ryuk has called CreateToolhelp32Snapshot to enumerate all running processes.

T1057
Process Discovery
MalwareFinal1stspy

Final1stspy obtains a list of running processes.

T1057
Process Discovery
MalwareMgBot

MgBot includes a module for establishing a process watchdog for itself, identifying if the MgBot process is still running.

T1057
Process Discovery
MalwareLockBit 2.0

LockBit 2.0 can determine if a running process has administrative privileges and terminate processes that interfere with encryption or exfiltration.

T1057
Process Discovery
MalwareZebrocy

Zebrocy uses the tasklist and wmic process get Capture, ExecutablePath commands to gather the processes running on the system.

T1057
Process Discovery
MalwarePandora

Pandora can monitor processes on a compromised host.

T1057
Process Discovery
MalwareFinFisher

FinFisher checks its parent process for indications that it is running in a sandbox setup.

T1057
Process Discovery
MalwareCobalt Strike

Cobalt Strike's Beacon payload can collect information on process details.

T1057
Process Discovery
MalwareSUNBURST

SUNBURST collected a list of process names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists.

T1057
Process Discovery
MalwareEvilBunny

EvilBunny has used EnumProcesses() to identify how many process are running in the environment.

T1057
Process Discovery
MalwareHotCroissant

HotCroissant has the ability to list running processes on the infected host.

T1057
Process Discovery
MalwareValak

Valak has the ability to enumerate running processes on a compromised host.

T1057
Process Discovery
MalwareTaidoor

Taidoor can use GetCurrentProcessId for process discovery.

T1057
Process Discovery
MalwareCaddyWiper

CaddyWiper can obtain a list of current processes.

T1057
Process Discovery
MalwareCyclops Blink

Cyclops Blink can enumerate the process it is currently running under.

T1057
Process Discovery
MalwareSeasalt

Seasalt has a command to perform a process listing.

T1057
Process Discovery
MalwareTajMahal

TajMahal has the ability to identify running processes and associated plugins on an infected host.

T1057
Process Discovery
MalwarePLEAD

PLEAD has the ability to list processes on the compromised host.

T1057
Process Discovery
MalwareIPsec Helper

IPsec Helper can identify the process it is currently running under and its number, and pass this back to a command and control node.

T1057
Process Discovery
MalwareCarbon

Carbon can list the processes on the victim’s machine.

T1057
Process Discovery
MalwareTRAILBLAZE

TRAILBLAZE has conducted process discovery by searching for specific named processes such as `/home/bin/web`.

T1057
Process Discovery
MalwareCardinal RAT

Cardinal RAT contains watchdog functionality that ensures its process is always running, else spawns a new instance.

T1057
Process Discovery
MalwareBISCUIT

BISCUIT has a command to enumerate running processes and identify their owners.

T1057
Process Discovery
MalwareGold Dragon

Gold Dragon checks the running processes on the victim’s machine.

T1057
Process Discovery
MalwareRamsay

Ramsay can gather a list of running processes by using Tasklist.

T1057
Process Discovery
MalwareAshTag

The AshTag AshenOrchestrator component has process management functionality.

T1057
Process Discovery
MalwareCarberp

Carberp has collected a list of running processes.

T1057
Process Discovery
MalwareNKAbuse

NKAbuse will check victim systems to ensure only one copy of the malware is running.

T1057
Process Discovery
MalwarePillowmint

Pillowmint can iterate through running processes every six seconds collecting a list of processes to capture from later.

T1057
Process Discovery
MalwareMacMa

MacMa can enumerate running processes.

T1057
Process Discovery
MalwareFunnyDream

FunnyDream has the ability to discover processes, including `Bka.exe` and `BkavUtil.exe`.

T1057
Process Discovery
MalwareSUNSPOT

SUNSPOT monitored running processes for instances of MsBuild.exe by hashing the name of each running process and comparing it to the corresponding value 0x53D525. It also extracted command-line arguments and individual arguments from the running MsBuild.exe process to identify the directory path of the Orion software Visual Studio solution.

T1057
Process Discovery
MalwareSysUpdate

SysUpdate can collect information about running processes.

T1057
Process Discovery
MalwareOutSteel

OutSteel can identify running processes on a compromised host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.