ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1057×

268 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list running processes.

T1057
Process Discovery
MalwareWarzoneRAT

WarzoneRAT can obtain a list of processes on a compromised host.

T1057
Process Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has enumerated processes by ID, name, or privileges.

T1057
Process Discovery
ToolShimRatReporter

ShimRatReporter listed all running processes on the machine.

T1057
Process Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate processes, including properties to determine if they have the Common Language Runtime (CLR) loaded.

T1057
Process Discovery
ToolPowerSploit

PowerSploit's Get-ProcessTokenPrivilege Privesc-PowerUp module can enumerate privileges for a given process.

T1057
Process Discovery
ToolTasklist

Tasklist can be used to discover processes running on a system.

T1057
Process Discovery
ToolEmpire

Empire can find information about processes running on local and remote systems.

T1057
Process Discovery
ToolPcShare

PcShare can obtain a list of running processes on a compromised host.

T1057
Process Discovery
ToolAsyncRAT

AsyncRAT can examine running processes to determine if a debugger is present.

T1057
Process Discovery
ToolBrute Ratel C4

Brute Ratel C4 can enumerate all processes and locate specific process IDs (PIDs).

T1057
Process Discovery
ToolRemcos

Remcos can discover running processes on compromised machines.

T1057
Process Discovery
ToolImminent Monitor

Imminent Monitor has a "Process Watcher" feature to monitor processes in case the client ever crashes or gets closed.

T1057
Process Discovery
ToolDonut

Donut includes subprojects that enumerate and identify information about Process Injection candidates.

T1057
Process Discovery
ToolIronNetInjector

IronNetInjector can identify processes via C# methods such as GetProcessesByName and running Tasklist with the Python os.popen function.

T1057
Process Discovery
ToolPupy

Pupy can list the running processes and get the process ID and parent process’s ID.

T1057
Process Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can locate GitHub Actions runner processes.

T1057
Process Discovery
MalwareDuqu

The discovery modules used with Duqu can collect information on process details.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.