Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareLizar | Lizar has a plugin designed to obtain a list of processes. |
| T1057 Process Discovery |
MalwareDtrack | Dtrack’s dropper can list all running processes. |
| T1057 Process Discovery |
MalwareLoudMiner | LoudMiner used the |
| T1057 Process Discovery |
MalwareAzorult | Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot. |
| T1057 Process Discovery |
MalwareBACKSPACE | BACKSPACE may collect information about running processes. |
| T1057 Process Discovery |
MalwareZox | Zox has the ability to list processes. |
| T1057 Process Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list running processes. |
| T1057 Process Discovery |
MalwareWarzoneRAT | WarzoneRAT can obtain a list of processes on a compromised host. |
| T1057 Process Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has enumerated processes by ID, name, or privileges. |
| T1057 Process Discovery |
ToolShimRatReporter | ShimRatReporter listed all running processes on the machine. |
| T1057 Process Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate processes, including properties to determine if they have the Common Language Runtime (CLR) loaded. |
| T1057 Process Discovery |
ToolPowerSploit | PowerSploit's |
| T1057 Process Discovery |
ToolTasklist | Tasklist can be used to discover processes running on a system. |
| T1057 Process Discovery |
ToolEmpire | Empire can find information about processes running on local and remote systems. |
| T1057 Process Discovery |
ToolPcShare | PcShare can obtain a list of running processes on a compromised host. |
| T1057 Process Discovery |
ToolAsyncRAT | AsyncRAT can examine running processes to determine if a debugger is present. |
| T1057 Process Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can enumerate all processes and locate specific process IDs (PIDs). |
| T1057 Process Discovery |
ToolRemcos | Remcos can discover running processes on compromised machines. |
| T1057 Process Discovery |
ToolImminent Monitor | Imminent Monitor has a "Process Watcher" feature to monitor processes in case the client ever crashes or gets closed. |
| T1057 Process Discovery |
ToolDonut | Donut includes subprojects that enumerate and identify information about Process Injection candidates. |
| T1057 Process Discovery |
ToolIronNetInjector | IronNetInjector can identify processes via C# methods such as |
| T1057 Process Discovery |
ToolPupy | Pupy can list the running processes and get the process ID and parent process’s ID. |
| T1057 Process Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can locate GitHub Actions runner processes. |
| T1057 Process Discovery |
MalwareDuqu | The discovery modules used with Duqu can collect information on process details. |
| T1059 Command and Scripting Interpreter |
MalwareNICECURL | NICECURL has provided an arbitrary command execution interface. |
| T1059 Command and Scripting Interpreter |
MalwareGet2 | Get2 has the ability to run executables with command-line arguments. |
| T1059 Command and Scripting Interpreter |
MalwareVersaMem | VersaMem was delivered as a Java Archive (JAR) that runs by attaching itself to the Apache Tomcat Java servlet and web server. |
| T1059 Command and Scripting Interpreter |
MalwareZeus Panda | Zeus Panda can launch remote scripts on the victim’s machine. |
| T1059 Command and Scripting Interpreter |
MalwareMatryoshka | Matryoshka is capable of providing Meterpreter shell access. |
| T1059 Command and Scripting Interpreter |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to create reverse shells with Perl scripts. |
| T1059 Command and Scripting Interpreter |
MalwareWINERACK | WINERACK can create a reverse shell that utilizes statically-linked Wine cmd.exe code to emulate Windows command prompt commands. |
| T1059 Command and Scripting Interpreter |
MalwareBonadan | Bonadan can create bind and reverse shells on the infected system. |
| T1059 Command and Scripting Interpreter |
MalwareRaspberry Robin | Raspberry Robin variants can be delivered via highly obfuscated Windows Script Files (WSF) for initial execution. |
| T1059 Command and Scripting Interpreter |
MalwareDarkComet | DarkComet can execute various types of scripts on the victim’s machine. |
| T1059 Command and Scripting Interpreter |
MalwareMuddyViper | MuddyViper has launched a reverse shell using a provided command line. |
| T1059 Command and Scripting Interpreter |
MalwareBandook | Bandook can support commands to execute Java-based payloads. |
| T1059 Command and Scripting Interpreter |
Malwaregh0st RAT | gh0st RAT is able to open a remote shell to execute commands. |
| T1059 Command and Scripting Interpreter |
MalwareSpeakUp | SpeakUp uses Perl scripts. |
| T1059 Command and Scripting Interpreter |
MalwareKessel | Kessel can create a reverse shell between the infected host and a specified system. |
| T1059 Command and Scripting Interpreter |
MalwareCHOPSTICK | CHOPSTICK is capable of performing remote command execution. |
| T1059 Command and Scripting Interpreter |
MalwareSLIGHTPULSE | SLIGHTPULSE contains functionality to execute arbitrary commands passed to it. |
| T1059 Command and Scripting Interpreter |
MalwareStarProxy | StarProxy has used the command line for execution of commands. |
| T1059 Command and Scripting Interpreter |
MalwareFIVEHANDS | FIVEHANDS can receive a command line argument to limit file encryption to specified directories. |
| T1059 Command and Scripting Interpreter |
ToolEmpire | Empire uses a command-line interface to interact with systems. |
| T1059 Command and Scripting Interpreter |
ToolImminent Monitor | Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts. |
| T1059 Command and Scripting Interpreter |
ToolDonut | Donut can generate shellcode outputs that execute via Ruby. |
| T1059 Command and Scripting Interpreter |
MalwareZeroCleare | ZeroCleare can receive command line arguments from an operator to corrupt the file system using the RawDisk driver. |
| T1059.001 PowerShell |
MalwareTrickBot | TrickBot has been known to use PowerShell to download new payloads, open documents, and upload data to command and control servers. |
| T1059.001 PowerShell |
MalwareBumblebee | Bumblebee can use PowerShell for execution. |
| T1059.001 PowerShell |
MalwareGRIFFON | GRIFFON has used PowerShell to execute the Meterpreter downloader TinyMet. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.