ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1056.002
GUI Input Capture
MalwareBundlore

Bundlore prompts the user for their credentials.

T1056.002
GUI Input Capture
MalwareLP-Notes

LP-Notes has displayed a fake Windows Security dialog box to prompt for Windows credentials.

T1056.002
GUI Input Capture
MalwareMetamorfo

Metamorfo has displayed fake forms on top of banking sites to intercept credentials from victims.

T1056.002
GUI Input Capture
MalwareCalisto

Calisto presents an input prompt asking for the user's login and password.

T1056.002
GUI Input Capture
MalwareProton

Proton prompts users for their credentials.

T1056.002
GUI Input Capture
MalwareXCSSET

XCSSET prompts the user to input credentials using a native macOS dialog box leveraging the system process /Applications/Safari.app/Contents/MacOS/SafariForWebKitDevelopment.

T1056.002
GUI Input Capture
MalwareDok

Dok prompts the user for credentials.

T1056.002
GUI Input Capture
ToolSILENTTRINITY

SILENTTRINITY's `credphisher.py` module can prompt a current user for their credentials.

T1056.003
Web Portal Capture
CampaignTriton Safety Instrumented System Attack

In the Triton Safety Instrumented System Attack, TEMP.Veles captured credentials as they were being changed by redirecting text-based login codes to websites they controlled.

T1056.003
Web Portal Capture
CampaignCutting Edge

During Cutting Edge, threat actors modified the JavaScript loaded by the Ivanti Connect Secure login page to capture credentials entered.

T1056.003
Web Portal Capture
GroupKimsuky

Kimsuky has collected credentials from a fake Google account login page.

T1056.003
Web Portal Capture
GroupWinter Vivern

Winter Vivern registered and hosted domains to allow for creation of web pages mimicking legitimate government email logon sites to collect logon information.

T1056.003
Web Portal Capture
MalwareWARPWIRE

WARPWIRE can capture credentials submitted during the web logon process in order to access layer seven applications such as RDP.

T1056.003
Web Portal Capture
MalwareIceApple

The IceApple OWA credential logger can monitor for OWA authentication requests and log the credentials.

T1056.004
Credential API Hooking
GroupPLATINUM

PLATINUM is capable of using Windows hook interfaces for information gathering such as credential access.

T1056.004
Credential API Hooking
MalwareTrickBot

TrickBot has the ability to capture RDP credentials by capturing the CredEnumerateA API

T1056.004
Credential API Hooking
MalwareRDFSNIFFER

RDFSNIFFER hooks several Win32 API functions to hijack elements of the remote system management user-interface.

T1056.004
Credential API Hooking
MalwareNOKKI

NOKKI uses the Windows call SetWindowsHookEx and begins injecting it into every GUI process running on the victim's machine.

T1056.004
Credential API Hooking
MalwareVersaMem

VersaMem hooked and overrided Versa's built-in authentication method, `setUserPassword`, to intercept plaintext credentials when submitted to the server.

T1056.004
Credential API Hooking
MalwareUrsnif

Ursnif has hooked APIs to perform a wide variety of information theft, such as monitoring traffic from browsers.

T1056.004
Credential API Hooking
MalwareZeus Panda

Zeus Panda hooks processes by leveraging its own IAT hooked functions.

T1056.004
Credential API Hooking
MalwareZebrocy

Zebrocy installs an application-defined Windows hook to get notified when a network drive has been attached, so it can then use the hook to call its RecordToFile file stealing method.

T1056.004
Credential API Hooking
MalwareFinFisher

FinFisher hooks processes by modifying IAT pointers to CreateWindowEx.

T1056.004
Credential API Hooking
MalwareCarberp

Carberp has hooked several Windows API functions to steal credentials.

T1056.004
Credential API Hooking
MalwareZxShell

ZxShell hooks several API functions to spawn system threads.

T1056.004
Credential API Hooking
ToolEmpire

Empire contains some modules that leverage API hooking to carry out tasks, such as netripper.

T1057
Process Discovery
CampaignKV Botnet Activity

Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation.

T1057
Process Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to obtain a list of all running processes.

T1057
Process Discovery
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of reading the PID for the Junos OS snmpd daemon.

T1057
Process Discovery
CampaignOperation Honeybee

During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`.

T1057
Process Discovery
CampaignC0015

During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes.

T1057
Process Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes.

T1057
Process Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used Tasklist on targeted systems.

T1057
Process Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `tasklist` command as part of their advanced reconnaissance.

T1057
Process Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries enumerated current running processes using `tasklist`.

T1057
Process Discovery
CampaignOperation Wocao

During Operation Wocao, the threat actors used `tasklist` to collect a list of running processes on an infected system.

T1057
Process Discovery
GroupAPT38

APT38 leveraged Sysmon to understand the processes, services in the organization.

T1057
Process Discovery
GroupAPT3

APT3 has a tool that can list out currently running processes.

T1057
Process Discovery
GroupKimsuky

Kimsuky can gather a list of all processes running on a victim's machine. Kimsuky has also obtained running processes on the victim device utilizing PowerShell cmdlet `Get-Process`.

T1057
Process Discovery
GroupVolt Typhoon

Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist.

T1057
Process Discovery
GroupHAFNIUM

HAFNIUM has used `tasklist` to enumerate processes.

T1057
Process Discovery
GroupMuddyWater

MuddyWater has used malware to obtain a list of running processes on the system.

T1057
Process Discovery
GroupGamaredon Group

Gamaredon Group has used tools to enumerate processes on target hosts including Process Explorer.

T1057
Process Discovery
GroupTeamTNT

TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools.

T1057
Process Discovery
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery.

T1057
Process Discovery
GroupAndariel

Andariel has used tasklist to enumerate processes and find a specific string.

T1057
Process Discovery
GroupSidewinder

Sidewinder has used tools to identify running processes on the victim's machine.

T1057
Process Discovery
GroupMustang Panda

Mustang Panda has used tasklist /v to determine active process information. Mustang Panda has also used TONESHELL malware to check the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler.

T1057
Process Discovery
GroupRocke

Rocke can detect a running process's PID on the infected machine.

T1057
Process Discovery
GroupUNC3886

UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.