Real-world descriptions of how a group, tool or campaign used a technique.
268 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareIxeshe | Ixeshe can list running processes. |
| T1057 Process Discovery |
Malware4H RAT | 4H RAT has the capability to obtain a listing of running processes (including loaded modules). |
| T1057 Process Discovery |
MalwareRogueRobin | RogueRobin checks the running processes for evidence it may be running in a sandbox environment. It specifically enumerates processes for Wireshark and Sysinternals. |
| T1057 Process Discovery |
MalwareStreamEx | StreamEx has the ability to enumerate processes. |
| T1057 Process Discovery |
MalwareNightClub | NightClub has the ability to use `GetWindowThreadProcessId` to identify the process behind a specified window. |
| T1057 Process Discovery |
MalwareSDBbot | SDBbot can enumerate a list of running processes on a compromised machine. |
| T1057 Process Discovery |
MalwareMosquito | Mosquito runs |
| T1057 Process Discovery |
MalwareRTM | RTM can obtain information about process integrity levels. |
| T1057 Process Discovery |
MalwareDerusbi | Derusbi collects current and parent process IDs. |
| T1057 Process Discovery |
MalwareSodaMaster | SodaMaster can search a list of running processes. |
| T1057 Process Discovery |
MalwareGrandoreiro | Grandoreiro can identify installed security tools based on process names. |
| T1057 Process Discovery |
MalwareZxxZ | ZxxZ has created a snapshot of running processes using `CreateToolhelp32Snapshot`. |
| T1057 Process Discovery |
MalwareBazar | Bazar can identity the current process on a compromised host. |
| T1057 Process Discovery |
MalwareRATANKBA | RATANKBA lists the system’s processes. |
| T1057 Process Discovery |
MalwareMoonWind | MoonWind has a command to return a list of running processes. |
| T1057 Process Discovery |
MalwareHiddenFace | HiddenFace can check running processes against a list of blocklisted applications. |
| T1057 Process Discovery |
MalwareRyuk | Ryuk has called |
| T1057 Process Discovery |
MalwareFinal1stspy | Final1stspy obtains a list of running processes. |
| T1057 Process Discovery |
MalwareMgBot | MgBot includes a module for establishing a process watchdog for itself, identifying if the MgBot process is still running. |
| T1057 Process Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can determine if a running process has administrative privileges and terminate processes that interfere with encryption or exfiltration. |
| T1057 Process Discovery |
MalwareZebrocy | Zebrocy uses the |
| T1057 Process Discovery |
MalwarePandora | Pandora can monitor processes on a compromised host. |
| T1057 Process Discovery |
MalwareFinFisher | FinFisher checks its parent process for indications that it is running in a sandbox setup. |
| T1057 Process Discovery |
MalwareCobalt Strike | Cobalt Strike's Beacon payload can collect information on process details. |
| T1057 Process Discovery |
MalwareSUNBURST | SUNBURST collected a list of process names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists. |
| T1057 Process Discovery |
MalwareEvilBunny | EvilBunny has used EnumProcesses() to identify how many process are running in the environment. |
| T1057 Process Discovery |
MalwareHotCroissant | HotCroissant has the ability to list running processes on the infected host. |
| T1057 Process Discovery |
MalwareValak | Valak has the ability to enumerate running processes on a compromised host. |
| T1057 Process Discovery |
MalwareTaidoor | Taidoor can use |
| T1057 Process Discovery |
MalwareCaddyWiper | CaddyWiper can obtain a list of current processes. |
| T1057 Process Discovery |
MalwareCyclops Blink | Cyclops Blink can enumerate the process it is currently running under. |
| T1057 Process Discovery |
MalwareSeasalt | Seasalt has a command to perform a process listing. |
| T1057 Process Discovery |
MalwareTajMahal | TajMahal has the ability to identify running processes and associated plugins on an infected host. |
| T1057 Process Discovery |
MalwarePLEAD | PLEAD has the ability to list processes on the compromised host. |
| T1057 Process Discovery |
MalwareIPsec Helper | IPsec Helper can identify the process it is currently running under and its number, and pass this back to a command and control node. |
| T1057 Process Discovery |
MalwareCarbon | Carbon can list the processes on the victim’s machine. |
| T1057 Process Discovery |
MalwareTRAILBLAZE | TRAILBLAZE has conducted process discovery by searching for specific named processes such as `/home/bin/web`. |
| T1057 Process Discovery |
MalwareCardinal RAT | Cardinal RAT contains watchdog functionality that ensures its process is always running, else spawns a new instance. |
| T1057 Process Discovery |
MalwareBISCUIT | BISCUIT has a command to enumerate running processes and identify their owners. |
| T1057 Process Discovery |
MalwareGold Dragon | Gold Dragon checks the running processes on the victim’s machine. |
| T1057 Process Discovery |
MalwareRamsay | Ramsay can gather a list of running processes by using Tasklist. |
| T1057 Process Discovery |
MalwareAshTag | The AshTag AshenOrchestrator component has process management functionality. |
| T1057 Process Discovery |
MalwareCarberp | Carberp has collected a list of running processes. |
| T1057 Process Discovery |
MalwareNKAbuse | NKAbuse will check victim systems to ensure only one copy of the malware is running. |
| T1057 Process Discovery |
MalwarePillowmint | Pillowmint can iterate through running processes every six seconds collecting a list of processes to capture from later. |
| T1057 Process Discovery |
MalwareMacMa | MacMa can enumerate running processes. |
| T1057 Process Discovery |
MalwareFunnyDream | FunnyDream has the ability to discover processes, including `Bka.exe` and `BkavUtil.exe`. |
| T1057 Process Discovery |
MalwareSUNSPOT | SUNSPOT monitored running processes for instances of |
| T1057 Process Discovery |
MalwareSysUpdate | SysUpdate can collect information about running processes. |
| T1057 Process Discovery |
MalwareOutSteel | OutSteel can identify running processes on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.