Real-world descriptions of how a group, tool or campaign used a technique.
268 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareKwampirs | Kwampirs collects a list of running services with the command |
| T1057 Process Discovery |
MalwareLAMEHUG | LAMEHUG can gather process information on targeted systems. |
| T1057 Process Discovery |
MalwareLookBack | LookBack can list running processes. |
| T1057 Process Discovery |
MalwareClop | Clop can enumerate all processes on the victim's machine. |
| T1057 Process Discovery |
MalwarePoetRAT | PoetRAT has the ability to list all running processes. |
| T1057 Process Discovery |
MalwareFELIXROOT | FELIXROOT collects a list of running processes. |
| T1057 Process Discovery |
MalwareZxShell | ZxShell has a command, ps, to obtain a listing of processes on the system. |
| T1057 Process Discovery |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has searched for running processes to include web or dsmdm. |
| T1057 Process Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1057 Process Discovery |
MalwareCannon | Cannon can obtain a list of processes running on the system. |
| T1057 Process Discovery |
MalwareWinnti for Windows | Winnti for Windows can check if the explorer.exe process is responsible for calling its install function. |
| T1057 Process Discovery |
MalwareBLACKCOFFEE | BLACKCOFFEE has the capability to discover processes. |
| T1057 Process Discovery |
MalwareKinsing | Kinsing has used ps to list processes. |
| T1057 Process Discovery |
MalwareMeteor | Meteor can check if a specific process is running, such as Kaspersky's `avp.exe`. |
| T1057 Process Discovery |
MalwarenjRAT | njRAT can search a list of running processes for Tr.exe. |
| T1057 Process Discovery |
MalwareZIPLINE | ZIPLINE can identify running processes and their names. |
| T1057 Process Discovery |
MalwareMaze | Maze has gathered all of the running system processes. |
| T1057 Process Discovery |
MalwareHIUPAN | HIUPAN has conducted process discovery to identify the PUBLOAD malware under the process WCBrowserWatcher.exe and will launch it from an install directory if it is not found. |
| T1057 Process Discovery |
MalwareChChes | ChChes collects its process identifier (PID) on the victim. |
| T1057 Process Discovery |
MalwarePowerStallion | PowerStallion has been used to monitor process lists. |
| T1057 Process Discovery |
MalwareJPIN | JPIN can list running processes. |
| T1057 Process Discovery |
MalwaremetaMain | metaMain can enumerate the processes that run on the platform. |
| T1057 Process Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor can gather process information. |
| T1057 Process Discovery |
MalwareLunarWeb | LunarWeb has used shell commands to list running processes. |
| T1057 Process Discovery |
MalwareKillDisk | KillDisk has called |
| T1057 Process Discovery |
MalwareQilin | Qilin can define specific processes to be terminated or left alone at execution. |
| T1057 Process Discovery |
MalwareSoreFang | SoreFang can enumerate processes on a victim machine through use of Tasklist. |
| T1057 Process Discovery |
MalwareSocksbot | Socksbot can list all running processes. |
| T1057 Process Discovery |
MalwareAgent Tesla | Agent Tesla can list the current running processes on the system. |
| T1057 Process Discovery |
MalwarePasam | Pasam creates a backdoor through which remote attackers can retrieve lists of running processes. |
| T1057 Process Discovery |
MalwarePOWERSTATS | POWERSTATS has used |
| T1057 Process Discovery |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can retrieve a list of running processes. |
| T1057 Process Discovery |
MalwareGoopy | Goopy has checked for the Google Updater process to ensure Goopy was loaded properly. |
| T1057 Process Discovery |
MalwareShadowPad | ShadowPad has collected the PID of a malicious process. |
| T1057 Process Discovery |
MalwareAstaroth | Astaroth searches for different processes on the system. |
| T1057 Process Discovery |
MalwareQakBot | QakBot has the ability to check running processes. |
| T1057 Process Discovery |
MalwareSYSCON | SYSCON has the ability to use Tasklist to list running processes. |
| T1057 Process Discovery |
MalwareGelsemium | Gelsemium can enumerate running processes. |
| T1057 Process Discovery |
MalwarejRAT | jRAT can query and kill system processes. |
| T1057 Process Discovery |
MalwareHelminth | |
| T1057 Process Discovery |
MalwareKomplex | The OsInfo function in Komplex collects a running process list. |
| T1057 Process Discovery |
MalwareINC Ransomware | INC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt. |
| T1057 Process Discovery |
MalwareWaterbear | Waterbear can identify the process for a specific security product. |
| T1057 Process Discovery |
MalwareComnie | Comnie uses the |
| T1057 Process Discovery |
MalwareLizar | Lizar has a plugin designed to obtain a list of processes. |
| T1057 Process Discovery |
MalwareDtrack | Dtrack’s dropper can list all running processes. |
| T1057 Process Discovery |
MalwareLoudMiner | LoudMiner used the |
| T1057 Process Discovery |
MalwareAzorult | Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot. |
| T1057 Process Discovery |
MalwareBACKSPACE | BACKSPACE may collect information about running processes. |
| T1057 Process Discovery |
MalwareZox | Zox has the ability to list processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.