ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareRansomHub

RansomHub can stop processes associated with files currently in use to maximize the impact of encryption.

T1057
Process Discovery
MalwareZeus Panda

Zeus Panda checks for running processes on the victim’s machine.

T1057
Process Discovery
MalwareGeminiDuke

GeminiDuke collects information on running processes and environment variables from the victim.

T1057
Process Discovery
MalwareHavoc

Havoc can enumerate processes on targeted hosts.

T1057
Process Discovery
MalwareFrameworkPOS

FrameworkPOS can enumerate and exclude selected processes on a compromised host to speed execution of memory scraping.

T1057
Process Discovery
MalwareGravityRAT

GravityRAT lists the running processes on the system.

T1057
Process Discovery
MalwareInvisibleFerret

InvisibleFerret has the capability to query installed programs and running processes. InvisibleFerret has also identified running processes using the Python project “psutil”.

T1057
Process Discovery
MalwareBankshot

Bankshot identifies processes and collects the process ids.

T1057
Process Discovery
MalwareStrongPity

StrongPity can determine if a user is logged in by checking to see if explorer.exe is running.

T1057
Process Discovery
MalwarePLAINTEE

PLAINTEE performs the tasklist command to list running processes.

T1057
Process Discovery
MalwareWinMM

WinMM sets a WH_CBT Windows hook to collect information on process creation.

T1057
Process Discovery
MalwareNebulae

Nebulae can enumerate processes on a target system.

T1057
Process Discovery
MalwareTONESHELL

TONESHELL has checked the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler. TONESHELL has also searched for running antivirus processes to include ESET’s antivirus associated executables ekrn.exe and egui.exe.

T1057
Process Discovery
MalwareUPSTYLE

UPSTYLE has the ability to read `/proc/self/cmdline` to see if it is running as a monitored process.

T1057
Process Discovery
MalwareKasidet

Kasidet has the ability to search for a given process name in processes currently running in the system.

T1057
Process Discovery
MalwareOceanSalt

OceanSalt can collect the name and ID for every process running on the system.

T1057
Process Discovery
MalwareBrave Prince

Brave Prince lists the running processes.

T1057
Process Discovery
MalwareMedusa Ransomware

Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates.

T1057
Process Discovery
MalwareRainyDay

RainyDay can enumerate processes on a target system.

T1057
Process Discovery
MalwareAppleSeed

AppleSeed can enumerate the current process on a compromised host.

T1057
Process Discovery
MalwaremacOS.OSAMiner

macOS.OSAMiner has used `ps ax | grep <name> | grep -v grep | ...` and `ps ax | grep -E...` to conduct process discovery.

T1057
Process Discovery
MalwareNETWIRE

NETWIRE can discover processes on compromised hosts.

T1057
Process Discovery
MalwareiKitten

iKitten lists the current processes running.

T1057
Process Discovery
MalwareBad Rabbit

Bad Rabbit can enumerate all running processes to compare hashes.

T1057
Process Discovery
MalwareAria-body

Aria-body has the ability to enumerate loaded modules for a process..

T1057
Process Discovery
MalwareEmotet

Emotet has been observed enumerating local processes.

T1057
Process Discovery
MalwareCrimson

Crimson contains a command to list processes.

T1057
Process Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate running processes.

T1057
Process Discovery
MalwareBADHATCH

BADHATCH can retrieve a list of running processes from a compromised machine.

T1057
Process Discovery
MalwareMachete

Machete has a component to check for running processes to look for web browsers.

T1057
Process Discovery
MalwareAvenger

Avenger has the ability to use Tasklist to identify running processes.

T1057
Process Discovery
MalwarePUBLOAD

PUBLOAD has used `tasklist` to gather running processes on victim host. PUBLOAD has also leveraged the `OpenEventA` Windows API function to check whether the same process was already running.

T1057
Process Discovery
MalwareSystemBC

SystemBC has the ability to enumerate running processes.

T1057
Process Discovery
MalwareDacls

Dacls can collect data on running and parent processes.

T1057
Process Discovery
MalwareWoody RAT

Woody RAT can call `NtQuerySystemProcessInformation` with `SystemProcessInformation` to enumerate all running processes, including associated information such as PID, parent PID, image name, and owner.

T1057
Process Discovery
MalwareMafalda

Mafalda can enumerate running processes on a machine.

T1057
Process Discovery
MalwareELMER

ELMER is capable of performing process listings.

T1057
Process Discovery
MalwareShrinkLocker

ShrinkLocker checks whether the Bitlocker Drive Encryption Tools service is running.

T1057
Process Discovery
MalwareSombRAT

SombRAT can use the getprocesslist command to enumerate processes on a compromised host.

T1057
Process Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can use `ps aux` to enumerate running processes.

T1057
Process Discovery
MalwareMobileOrder

MobileOrder has a command to upload information about all running processes to its C2 server.

T1057
Process Discovery
MalwareInvisiMole

InvisiMole can obtain a list of running processes.

T1057
Process Discovery
MalwareApostle

Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files.

T1057
Process Discovery
MalwareVolgmer

Volgmer can gather a list of processes.

T1057
Process Discovery
MalwareWINERACK

WINERACK can enumerate processes.

T1057
Process Discovery
MalwareFruitFly

FruitFly has the ability to list processes on the system.

T1057
Process Discovery
MalwareSkidmap

Skidmap has monitored critical processes to ensure resiliency.

T1057
Process Discovery
MalwareBonadan

Bonadan can use the ps command to discover other cryptocurrency miners active on the system.

T1057
Process Discovery
MalwareConti

Conti can enumerate through all open processes to search for any that have the string “sql” in their process name.

T1057
Process Discovery
MalwareRaspberry Robin

Raspberry Robin can identify processes running on the victim machine, such as security software, during execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.