Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
GroupAPT37 | APT37's Freenki malware lists running processes using the Microsoft Windows API. |
| T1057 Process Discovery |
GroupOilRig | OilRig has run |
| T1057 Process Discovery |
GroupHigaisa | Higaisa’s shellcode attempted to find the process ID of the current process. |
| T1057 Process Discovery |
GroupTropic Trooper | Tropic Trooper is capable of enumerating the running processes on the system using |
| T1057 Process Discovery |
GroupKe3chang | Ke3chang performs process discovery using |
| T1057 Process Discovery |
GroupAPT1 | APT1 gathered a list of running processes on the system using |
| T1057 Process Discovery |
GroupTurla | Turla surveys a system upon check-in to discover running processes using the |
| T1057 Process Discovery |
GroupStorm-0501 | Storm-0501 has discovered running processes through `tasklist.exe`. |
| T1057 Process Discovery |
GroupPoseidon Group | After compromising a victim, Poseidon Group lists all running processes. |
| T1057 Process Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers a list of running processes. |
| T1057 Process Discovery |
GroupChimera | Chimera has used |
| T1057 Process Discovery |
GroupMirrorFace | MirrorFace has used Tasklist on compromised hosts for discovery. |
| T1057 Process Discovery |
GroupMedusa Group | Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094. |
| T1057 Process Discovery |
GroupDarkhotel | Darkhotel malware can collect a list of running processes on a system. |
| T1057 Process Discovery |
GroupDeep Panda | Deep Panda uses the Microsoft Tasklist utility to list processes running on systems. |
| T1057 Process Discovery |
GroupWindshift | Windshift has used malware to enumerate active processes. |
| T1057 Process Discovery |
GroupToddyCat | ToddyCat has run `cmd /c start /b tasklist` to enumerate processes. |
| T1057 Process Discovery |
GroupAPT28 | An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions. |
| T1057 Process Discovery |
GroupAPT5 | APT5 has used Windows-based utilities to carry out tasks including tasklist.exe. |
| T1057 Process Discovery |
GroupWinnti Group | Winnti Group looked for a specific process running on infected servers. |
| T1057 Process Discovery |
GroupLazarus Group | Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times. |
| T1057 Process Discovery |
GroupEarth Lusca | Earth Lusca has used Tasklist to obtain information from a compromised host. |
| T1057 Process Discovery |
GroupMolerats | Molerats actors obtained a list of active processes on the victim and sent them to C2 servers. |
| T1057 Process Discovery |
GroupInception | Inception has used a reconnaissance module to identify active processes and other associated loaded modules. |
| T1057 Process Discovery |
GroupPlay | Play has used the information stealer Grixba to check for a list of security processes. |
| T1057 Process Discovery |
GroupHEXANE | HEXANE has enumerated processes on targeted systems. |
| T1057 Process Discovery |
GroupMagic Hound | Magic Hound malware can list running processes. |
| T1057 Process Discovery |
MalwareTrickBot | TrickBot uses module networkDll for process list discovery. |
| T1057 Process Discovery |
MalwarePowerDuke | PowerDuke has a command to list the victim's processes. |
| T1057 Process Discovery |
MalwareEKANS | EKANS looks for processes from a hard-coded list. |
| T1057 Process Discovery |
MalwareNinja | Ninja can enumerate processes on a targeted host. |
| T1057 Process Discovery |
MalwareRCSession | RCSession can identify processes based on PID. |
| T1057 Process Discovery |
MalwareSynAck | SynAck enumerates all running processes. |
| T1057 Process Discovery |
MalwareBumblebee | Bumblebee can identify processes associated with analytical tools. |
| T1057 Process Discovery |
MalwareBRICKSTORM | BRICKSTORM has the ability to check if it is running as an active child process through the detection of a specific environment variable. |
| T1057 Process Discovery |
MalwareProxysvc | Proxysvc lists processes running on the system. |
| T1057 Process Discovery |
MalwareOrz | Orz can gather a process list from the victim. |
| T1057 Process Discovery |
Malwareyty | yty gets an output of running processes using the |
| T1057 Process Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about running processes. |
| T1057 Process Discovery |
MalwareRotaJakiro | RotaJakiro can monitor the `/proc/[PID]` directory of known RotaJakiro processes as a part of its persistence when executing with non-root permissions. If the process is found dead, it resurrects the process. RotaJakiro processes can be matched to an associated Advisory Lock, in the `/proc/locks` folder, to ensure it doesn't spawn more than one process. |
| T1057 Process Discovery |
MalwareAvosLocker | AvosLocker has discovered system processes by calling `RmGetList`. |
| T1057 Process Discovery |
MalwareGet2 | Get2 has the ability to identify running processes on an infected host. |
| T1057 Process Discovery |
MalwarePOWRUNER | POWRUNER may collect process information by running |
| T1057 Process Discovery |
MalwareKOPILUWAK | KOPILUWAK can enumerate current running processes on the targeted machine. |
| T1057 Process Discovery |
MalwarePAKLOG | PAKLOG has detected and logged the full path of processes active in the foreground using Windows API calls. |
| T1057 Process Discovery |
MalwareCOATHANGER | COATHANGER will query running process information to determine subsequent program execution flow. |
| T1057 Process Discovery |
MalwareSardonic | Sardonic has the ability to execute the `tasklist` command. |
| T1057 Process Discovery |
MalwareHALFBAKED | HALFBAKED can obtain information about running processes on the victim. |
| T1057 Process Discovery |
MalwareKEYMARBLE | KEYMARBLE can obtain a list of running processes on the system. |
| T1057 Process Discovery |
MalwareUrsnif | Ursnif has gathered information about running processes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.