ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
GroupAPT37

APT37's Freenki malware lists running processes using the Microsoft Windows API.

T1057
Process Discovery
GroupOilRig

OilRig has run tasklist on a victim's machine and used infostealers to capture processes.

T1057
Process Discovery
GroupHigaisa

Higaisa’s shellcode attempted to find the process ID of the current process.

T1057
Process Discovery
GroupTropic Trooper

Tropic Trooper is capable of enumerating the running processes on the system using pslist.

T1057
Process Discovery
GroupKe3chang

Ke3chang performs process discovery using tasklist commands.

T1057
Process Discovery
GroupAPT1

APT1 gathered a list of running processes on the system using tasklist /v.

T1057
Process Discovery
GroupTurla

Turla surveys a system upon check-in to discover running processes using the tasklist /v command. Turla RPC backdoors have also enumerated processes associated with specific open ports or named pipes.

T1057
Process Discovery
GroupStorm-0501

Storm-0501 has discovered running processes through `tasklist.exe`.

T1057
Process Discovery
GroupPoseidon Group

After compromising a victim, Poseidon Group lists all running processes.

T1057
Process Discovery
GroupStealth Falcon

Stealth Falcon malware gathers a list of running processes.

T1057
Process Discovery
GroupChimera

Chimera has used tasklist to enumerate processes.

T1057
Process Discovery
GroupMirrorFace

MirrorFace has used Tasklist on compromised hosts for discovery.

T1057
Process Discovery
GroupMedusa Group

Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094.

T1057
Process Discovery
GroupDarkhotel

Darkhotel malware can collect a list of running processes on a system.

T1057
Process Discovery
GroupDeep Panda

Deep Panda uses the Microsoft Tasklist utility to list processes running on systems.

T1057
Process Discovery
GroupWindshift

Windshift has used malware to enumerate active processes.

T1057
Process Discovery
GroupToddyCat

ToddyCat has run `cmd /c start /b tasklist` to enumerate processes.

T1057
Process Discovery
GroupAPT28

An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions.

T1057
Process Discovery
GroupAPT5

APT5 has used Windows-based utilities to carry out tasks including tasklist.exe.

T1057
Process Discovery
GroupWinnti Group

Winnti Group looked for a specific process running on infected servers.

T1057
Process Discovery
GroupLazarus Group

Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times.

T1057
Process Discovery
GroupEarth Lusca

Earth Lusca has used Tasklist to obtain information from a compromised host.

T1057
Process Discovery
GroupMolerats

Molerats actors obtained a list of active processes on the victim and sent them to C2 servers.

T1057
Process Discovery
GroupInception

Inception has used a reconnaissance module to identify active processes and other associated loaded modules.

T1057
Process Discovery
GroupPlay

Play has used the information stealer Grixba to check for a list of security processes.

T1057
Process Discovery
GroupHEXANE

HEXANE has enumerated processes on targeted systems.

T1057
Process Discovery
GroupMagic Hound

Magic Hound malware can list running processes.

T1057
Process Discovery
MalwareTrickBot

TrickBot uses module networkDll for process list discovery.

T1057
Process Discovery
MalwarePowerDuke

PowerDuke has a command to list the victim's processes.

T1057
Process Discovery
MalwareEKANS

EKANS looks for processes from a hard-coded list.

T1057
Process Discovery
MalwareNinja

Ninja can enumerate processes on a targeted host.

T1057
Process Discovery
MalwareRCSession

RCSession can identify processes based on PID.

T1057
Process Discovery
MalwareSynAck

SynAck enumerates all running processes.

T1057
Process Discovery
MalwareBumblebee

Bumblebee can identify processes associated with analytical tools.

T1057
Process Discovery
MalwareBRICKSTORM

BRICKSTORM has the ability to check if it is running as an active child process through the detection of a specific environment variable.

T1057
Process Discovery
MalwareProxysvc

Proxysvc lists processes running on the system.

T1057
Process Discovery
MalwareOrz

Orz can gather a process list from the victim.

T1057
Process Discovery
Malwareyty

yty gets an output of running processes using the tasklist command.

T1057
Process Discovery
MalwareBackdoor.Oldrea

Backdoor.Oldrea collects information about running processes.

T1057
Process Discovery
MalwareRotaJakiro

RotaJakiro can monitor the `/proc/[PID]` directory of known RotaJakiro processes as a part of its persistence when executing with non-root permissions. If the process is found dead, it resurrects the process. RotaJakiro processes can be matched to an associated Advisory Lock, in the `/proc/locks` folder, to ensure it doesn't spawn more than one process.

T1057
Process Discovery
MalwareAvosLocker

AvosLocker has discovered system processes by calling `RmGetList`.

T1057
Process Discovery
MalwareGet2

Get2 has the ability to identify running processes on an infected host.

T1057
Process Discovery
MalwarePOWRUNER

POWRUNER may collect process information by running tasklist on a victim.

T1057
Process Discovery
MalwareKOPILUWAK

KOPILUWAK can enumerate current running processes on the targeted machine.

T1057
Process Discovery
MalwarePAKLOG

PAKLOG has detected and logged the full path of processes active in the foreground using Windows API calls.

T1057
Process Discovery
MalwareCOATHANGER

COATHANGER will query running process information to determine subsequent program execution flow.

T1057
Process Discovery
MalwareSardonic

Sardonic has the ability to execute the `tasklist` command.

T1057
Process Discovery
MalwareHALFBAKED

HALFBAKED can obtain information about running processes on the victim.

T1057
Process Discovery
MalwareKEYMARBLE

KEYMARBLE can obtain a list of running processes on the system.

T1057
Process Discovery
MalwareUrsnif

Ursnif has gathered information about running processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.