ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1057×

268 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareKwampirs

Kwampirs collects a list of running services with the command tasklist /v.

T1057
Process Discovery
MalwareLAMEHUG

LAMEHUG can gather process information on targeted systems.

T1057
Process Discovery
MalwareLookBack

LookBack can list running processes.

T1057
Process Discovery
MalwareClop

Clop can enumerate all processes on the victim's machine.

T1057
Process Discovery
MalwarePoetRAT

PoetRAT has the ability to list all running processes.

T1057
Process Discovery
MalwareFELIXROOT

FELIXROOT collects a list of running processes.

T1057
Process Discovery
MalwareZxShell

ZxShell has a command, ps, to obtain a listing of processes on the system.

T1057
Process Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has searched for running processes to include web or dsmdm.

T1057
Process Discovery
MalwareBabyShark

BabyShark has executed the tasklist command.

T1057
Process Discovery
MalwareCannon

Cannon can obtain a list of processes running on the system.

T1057
Process Discovery
MalwareWinnti for Windows

Winnti for Windows can check if the explorer.exe process is responsible for calling its install function.

T1057
Process Discovery
MalwareBLACKCOFFEE

BLACKCOFFEE has the capability to discover processes.

T1057
Process Discovery
MalwareKinsing

Kinsing has used ps to list processes.

T1057
Process Discovery
MalwareMeteor

Meteor can check if a specific process is running, such as Kaspersky's `avp.exe`.

T1057
Process Discovery
MalwarenjRAT

njRAT can search a list of running processes for Tr.exe.

T1057
Process Discovery
MalwareZIPLINE

ZIPLINE can identify running processes and their names.

T1057
Process Discovery
MalwareMaze

Maze has gathered all of the running system processes.

T1057
Process Discovery
MalwareHIUPAN

HIUPAN has conducted process discovery to identify the PUBLOAD malware under the process WCBrowserWatcher.exe and will launch it from an install directory if it is not found.

T1057
Process Discovery
MalwareChChes

ChChes collects its process identifier (PID) on the victim.

T1057
Process Discovery
MalwarePowerStallion

PowerStallion has been used to monitor process lists.

T1057
Process Discovery
MalwareJPIN

JPIN can list running processes.

T1057
Process Discovery
MalwaremetaMain

metaMain can enumerate the processes that run on the platform.

T1057
Process Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can gather process information.

T1057
Process Discovery
MalwareLunarWeb

LunarWeb has used shell commands to list running processes.

T1057
Process Discovery
MalwareKillDisk

KillDisk has called GetCurrentProcess.

T1057
Process Discovery
MalwareQilin

Qilin can define specific processes to be terminated or left alone at execution.

T1057
Process Discovery
MalwareSoreFang

SoreFang can enumerate processes on a victim machine through use of Tasklist.

T1057
Process Discovery
MalwareSocksbot

Socksbot can list all running processes.

T1057
Process Discovery
MalwareAgent Tesla

Agent Tesla can list the current running processes on the system.

T1057
Process Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve lists of running processes.

T1057
Process Discovery
MalwarePOWERSTATS

POWERSTATS has used get_tasklist to discover processes on the compromised host.

T1057
Process Discovery
MalwareLinfo

Linfo creates a backdoor through which remote attackers can retrieve a list of running processes.

T1057
Process Discovery
MalwareGoopy

Goopy has checked for the Google Updater process to ensure Goopy was loaded properly.

T1057
Process Discovery
MalwareShadowPad

ShadowPad has collected the PID of a malicious process.

T1057
Process Discovery
MalwareAstaroth

Astaroth searches for different processes on the system.

T1057
Process Discovery
MalwareQakBot

QakBot has the ability to check running processes.

T1057
Process Discovery
MalwareSYSCON

SYSCON has the ability to use Tasklist to list running processes.

T1057
Process Discovery
MalwareGelsemium

Gelsemium can enumerate running processes.

T1057
Process Discovery
MalwarejRAT

jRAT can query and kill system processes.

T1057
Process Discovery
MalwareHelminth

Helminth has used Tasklist to get information on processes.

T1057
Process Discovery
MalwareKomplex

The OsInfo function in Komplex collects a running process list.

T1057
Process Discovery
MalwareINC Ransomware

INC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt.

T1057
Process Discovery
MalwareWaterbear

Waterbear can identify the process for a specific security product.

T1057
Process Discovery
MalwareComnie

Comnie uses the tasklist to view running processes on the victim’s machine.

T1057
Process Discovery
MalwareLizar

Lizar has a plugin designed to obtain a list of processes.

T1057
Process Discovery
MalwareDtrack

Dtrack’s dropper can list all running processes.

T1057
Process Discovery
MalwareLoudMiner

LoudMiner used the ps command to monitor the running processes on the system.

T1057
Process Discovery
MalwareAzorult

Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot.

T1057
Process Discovery
MalwareBACKSPACE

BACKSPACE may collect information about running processes.

T1057
Process Discovery
MalwareZox

Zox has the ability to list processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.