ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

11362 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareLizar

Lizar has a plugin designed to obtain a list of processes.

T1057
Process Discovery
MalwareDtrack

Dtrack’s dropper can list all running processes.

T1057
Process Discovery
MalwareLoudMiner

LoudMiner used the ps command to monitor the running processes on the system.

T1057
Process Discovery
MalwareAzorult

Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot.

T1057
Process Discovery
MalwareBACKSPACE

BACKSPACE may collect information about running processes.

T1057
Process Discovery
MalwareZox

Zox has the ability to list processes.

T1057
Process Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list running processes.

T1057
Process Discovery
MalwareWarzoneRAT

WarzoneRAT can obtain a list of processes on a compromised host.

T1057
Process Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has enumerated processes by ID, name, or privileges.

T1057
Process Discovery
ToolShimRatReporter

ShimRatReporter listed all running processes on the machine.

T1057
Process Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate processes, including properties to determine if they have the Common Language Runtime (CLR) loaded.

T1057
Process Discovery
ToolPowerSploit

PowerSploit's Get-ProcessTokenPrivilege Privesc-PowerUp module can enumerate privileges for a given process.

T1057
Process Discovery
ToolTasklist

Tasklist can be used to discover processes running on a system.

T1057
Process Discovery
ToolEmpire

Empire can find information about processes running on local and remote systems.

T1057
Process Discovery
ToolPcShare

PcShare can obtain a list of running processes on a compromised host.

T1057
Process Discovery
ToolAsyncRAT

AsyncRAT can examine running processes to determine if a debugger is present.

T1057
Process Discovery
ToolBrute Ratel C4

Brute Ratel C4 can enumerate all processes and locate specific process IDs (PIDs).

T1057
Process Discovery
ToolRemcos

Remcos can discover running processes on compromised machines.

T1057
Process Discovery
ToolImminent Monitor

Imminent Monitor has a "Process Watcher" feature to monitor processes in case the client ever crashes or gets closed.

T1057
Process Discovery
ToolDonut

Donut includes subprojects that enumerate and identify information about Process Injection candidates.

T1057
Process Discovery
ToolIronNetInjector

IronNetInjector can identify processes via C# methods such as GetProcessesByName and running Tasklist with the Python os.popen function.

T1057
Process Discovery
ToolPupy

Pupy can list the running processes and get the process ID and parent process’s ID.

T1057
Process Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can locate GitHub Actions runner processes.

T1057
Process Discovery
MalwareDuqu

The discovery modules used with Duqu can collect information on process details.

T1059
Command and Scripting Interpreter
MalwareNICECURL

NICECURL has provided an arbitrary command execution interface.

T1059
Command and Scripting Interpreter
MalwareGet2

Get2 has the ability to run executables with command-line arguments.

T1059
Command and Scripting Interpreter
MalwareVersaMem

VersaMem was delivered as a Java Archive (JAR) that runs by attaching itself to the Apache Tomcat Java servlet and web server.

T1059
Command and Scripting Interpreter
MalwareZeus Panda

Zeus Panda can launch remote scripts on the victim’s machine.

T1059
Command and Scripting Interpreter
MalwareMatryoshka

Matryoshka is capable of providing Meterpreter shell access.

T1059
Command and Scripting Interpreter
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to create reverse shells with Perl scripts.

T1059
Command and Scripting Interpreter
MalwareWINERACK

WINERACK can create a reverse shell that utilizes statically-linked Wine cmd.exe code to emulate Windows command prompt commands.

T1059
Command and Scripting Interpreter
MalwareBonadan

Bonadan can create bind and reverse shells on the infected system.

T1059
Command and Scripting Interpreter
MalwareRaspberry Robin

Raspberry Robin variants can be delivered via highly obfuscated Windows Script Files (WSF) for initial execution.

T1059
Command and Scripting Interpreter
MalwareDarkComet

DarkComet can execute various types of scripts on the victim’s machine.

T1059
Command and Scripting Interpreter
MalwareMuddyViper

MuddyViper has launched a reverse shell using a provided command line.

T1059
Command and Scripting Interpreter
MalwareBandook

Bandook can support commands to execute Java-based payloads.

T1059
Command and Scripting Interpreter
Malwaregh0st RAT

gh0st RAT is able to open a remote shell to execute commands.

T1059
Command and Scripting Interpreter
MalwareSpeakUp

SpeakUp uses Perl scripts.

T1059
Command and Scripting Interpreter
MalwareKessel

Kessel can create a reverse shell between the infected host and a specified system.

T1059
Command and Scripting Interpreter
MalwareCHOPSTICK

CHOPSTICK is capable of performing remote command execution.

T1059
Command and Scripting Interpreter
MalwareSLIGHTPULSE

SLIGHTPULSE contains functionality to execute arbitrary commands passed to it.

T1059
Command and Scripting Interpreter
MalwareStarProxy

StarProxy has used the command line for execution of commands.

T1059
Command and Scripting Interpreter
MalwareFIVEHANDS

FIVEHANDS can receive a command line argument to limit file encryption to specified directories.

T1059
Command and Scripting Interpreter
ToolEmpire

Empire uses a command-line interface to interact with systems.

T1059
Command and Scripting Interpreter
ToolImminent Monitor

Imminent Monitor has a CommandPromptPacket and ScriptPacket module(s) for creating a remote shell and executing scripts.

T1059
Command and Scripting Interpreter
ToolDonut

Donut can generate shellcode outputs that execute via Ruby.

T1059
Command and Scripting Interpreter
MalwareZeroCleare

ZeroCleare can receive command line arguments from an operator to corrupt the file system using the RawDisk driver.

T1059.001
PowerShell
MalwareTrickBot

TrickBot has been known to use PowerShell to download new payloads, open documents, and upload data to command and control servers.

T1059.001
PowerShell
MalwareBumblebee

Bumblebee can use PowerShell for execution.

T1059.001
PowerShell
MalwareGRIFFON

GRIFFON has used PowerShell to execute the Meterpreter downloader TinyMet.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.