Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1056.002 GUI Input Capture |
MalwareBundlore | Bundlore prompts the user for their credentials. |
| T1056.002 GUI Input Capture |
MalwareLP-Notes | LP-Notes has displayed a fake Windows Security dialog box to prompt for Windows credentials. |
| T1056.002 GUI Input Capture |
MalwareMetamorfo | Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims. |
| T1056.002 GUI Input Capture |
MalwareCalisto | Calisto presents an input prompt asking for the user's login and password. |
| T1056.002 GUI Input Capture |
MalwareProton | Proton prompts users for their credentials. |
| T1056.002 GUI Input Capture |
MalwareXCSSET | XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process |
| T1056.002 GUI Input Capture |
MalwareDok | Dok prompts the user for credentials. |
| T1056.002 GUI Input Capture |
ToolSILENTTRINITY | SILENTTRINITY's `credphisher.py` module can prompt a current user for their credentials. |
| T1056.003 Web Portal Capture |
CampaignTriton Safety Instrumented System Attack | In the Triton Safety Instrumented System Attack, TEMP.Veles captured credentials as they were being changed by redirecting text-based login codes to websites they controlled. |
| T1056.003 Web Portal Capture |
CampaignCutting Edge | During Cutting Edge, threat actors modified the JavaScript loaded by the Ivanti Connect Secure login page to capture credentials entered. |
| T1056.003 Web Portal Capture |
GroupKimsuky | Kimsuky has collected credentials from a fake Google account login page. |
| T1056.003 Web Portal Capture |
GroupWinter Vivern | Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information. |
| T1056.003 Web Portal Capture |
MalwareWARPWIRE | WARPWIRE can capture credentials submitted during the web logon process in order to access layer seven applications such as RDP. |
| T1056.003 Web Portal Capture |
MalwareIceApple | The IceApple OWA credential logger can monitor for OWA authentication requests and log the credentials. |
| T1056.004 Credential API Hooking |
GroupPLATINUM | PLATINUM is capable of using Windows hook interfaces for information gathering such as credential access. |
| T1056.004 Credential API Hooking |
MalwareTrickBot | TrickBot has the ability to capture RDP credentials by capturing the |
| T1056.004 Credential API Hooking |
MalwareRDFSNIFFER | RDFSNIFFER hooks several Win32 API functions to hijack elements of the remote system management user-interface. |
| T1056.004 Credential API Hooking |
MalwareNOKKI | NOKKI uses the Windows call SetWindowsHookEx and begins injecting it into every GUI process running on the victim's machine. |
| T1056.004 Credential API Hooking |
MalwareVersaMem | VersaMem hooked and overrided Versa's built-in authentication method, `setUserPassword`, to intercept plaintext credentials when submitted to the server. |
| T1056.004 Credential API Hooking |
MalwareUrsnif | Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers. |
| T1056.004 Credential API Hooking |
MalwareZeus Panda | Zeus Panda hooks processes by leveraging its own IAT hooked functions. |
| T1056.004 Credential API Hooking |
MalwareZebrocy | Zebrocy installs an application-defined Windows hook to get notified when a network drive has been attached, so it can then use the hook to call its RecordToFile file stealing method. |
| T1056.004 Credential API Hooking |
MalwareFinFisher | FinFisher hooks processes by modifying IAT pointers to CreateWindowEx. |
| T1056.004 Credential API Hooking |
MalwareCarberp | Carberp has hooked several Windows API functions to steal credentials. |
| T1056.004 Credential API Hooking |
MalwareZxShell | ZxShell hooks several API functions to spawn system threads. |
| T1056.004 Credential API Hooking |
ToolEmpire | Empire contains some modules that leverage API hooking to carry out tasks, such as netripper. |
| T1057 Process Discovery |
CampaignKV Botnet Activity | Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation. |
| T1057 Process Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to obtain a list of all running processes. |
| T1057 Process Discovery |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of reading the PID for the Junos OS snmpd daemon. |
| T1057 Process Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`. |
| T1057 Process Discovery |
CampaignC0015 | During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes. |
| T1057 Process Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes. |
| T1057 Process Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used Tasklist on targeted systems. |
| T1057 Process Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `tasklist` command as part of their advanced reconnaissance. |
| T1057 Process Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries enumerated current running processes using `tasklist`. |
| T1057 Process Discovery |
CampaignOperation Wocao | During Operation Wocao, the threat actors used `tasklist` to collect a list of running processes on an infected system. |
| T1057 Process Discovery |
GroupAPT38 | APT38 leveraged Sysmon to understand the processes, services in the organization. |
| T1057 Process Discovery |
GroupAPT3 | APT3 has a tool that can list out currently running processes. |
| T1057 Process Discovery |
GroupKimsuky | Kimsuky can gather a list of all processes running on a victim's machine. Kimsuky has also obtained running processes on the victim device utilizing PowerShell cmdlet `Get-Process`. |
| T1057 Process Discovery |
GroupVolt Typhoon | Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist. |
| T1057 Process Discovery |
GroupHAFNIUM | HAFNIUM has used `tasklist` to enumerate processes. |
| T1057 Process Discovery |
GroupMuddyWater | MuddyWater has used malware to obtain a list of running processes on the system. |
| T1057 Process Discovery |
GroupGamaredon Group | Gamaredon Group has used tools to enumerate processes on target hosts including Process Explorer. |
| T1057 Process Discovery |
GroupTeamTNT | TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools. |
| T1057 Process Discovery |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery. |
| T1057 Process Discovery |
GroupAndariel | Andariel has used |
| T1057 Process Discovery |
GroupSidewinder | Sidewinder has used tools to identify running processes on the victim's machine. |
| T1057 Process Discovery |
GroupMustang Panda | Mustang Panda has used |
| T1057 Process Discovery |
GroupRocke | Rocke can detect a running process's PID on the infected machine. |
| T1057 Process Discovery |
GroupUNC3886 | UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.