Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareRansomHub | RansomHub can stop processes associated with files currently in use to maximize the impact of encryption. |
| T1057 Process Discovery |
MalwareZeus Panda | Zeus Panda checks for running processes on the victim’s machine. |
| T1057 Process Discovery |
MalwareGeminiDuke | GeminiDuke collects information on running processes and environment variables from the victim. |
| T1057 Process Discovery |
MalwareHavoc | Havoc can enumerate processes on targeted hosts. |
| T1057 Process Discovery |
MalwareFrameworkPOS | FrameworkPOS can enumerate and exclude selected processes on a compromised host to speed execution of memory scraping. |
| T1057 Process Discovery |
MalwareGravityRAT | GravityRAT lists the running processes on the system. |
| T1057 Process Discovery |
MalwareInvisibleFerret | InvisibleFerret has the capability to query installed programs and running processes. InvisibleFerret has also identified running processes using the Python project “psutil”. |
| T1057 Process Discovery |
MalwareBankshot | Bankshot identifies processes and collects the process ids. |
| T1057 Process Discovery |
MalwareStrongPity | StrongPity can determine if a user is logged in by checking to see if explorer.exe is running. |
| T1057 Process Discovery |
MalwarePLAINTEE | PLAINTEE performs the |
| T1057 Process Discovery |
MalwareWinMM | WinMM sets a WH_CBT Windows hook to collect information on process creation. |
| T1057 Process Discovery |
MalwareNebulae | Nebulae can enumerate processes on a target system. |
| T1057 Process Discovery |
MalwareTONESHELL | TONESHELL has checked the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler. TONESHELL has also searched for running antivirus processes to include ESET’s antivirus associated executables ekrn.exe and egui.exe. |
| T1057 Process Discovery |
MalwareUPSTYLE | UPSTYLE has the ability to read `/proc/self/cmdline` to see if it is running as a monitored process. |
| T1057 Process Discovery |
MalwareKasidet | Kasidet has the ability to search for a given process name in processes currently running in the system. |
| T1057 Process Discovery |
MalwareOceanSalt | OceanSalt can collect the name and ID for every process running on the system. |
| T1057 Process Discovery |
MalwareBrave Prince | Brave Prince lists the running processes. |
| T1057 Process Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has utilized an encoded list of the processes that it detects and terminates. |
| T1057 Process Discovery |
MalwareRainyDay | RainyDay can enumerate processes on a target system. |
| T1057 Process Discovery |
MalwareAppleSeed | AppleSeed can enumerate the current process on a compromised host. |
| T1057 Process Discovery |
MalwaremacOS.OSAMiner | macOS.OSAMiner has used `ps ax | grep <name> | grep -v grep | ...` and `ps ax | grep -E...` to conduct process discovery. |
| T1057 Process Discovery |
MalwareNETWIRE | NETWIRE can discover processes on compromised hosts. |
| T1057 Process Discovery |
MalwareiKitten | iKitten lists the current processes running. |
| T1057 Process Discovery |
MalwareBad Rabbit | Bad Rabbit can enumerate all running processes to compare hashes. |
| T1057 Process Discovery |
MalwareAria-body | Aria-body has the ability to enumerate loaded modules for a process.. |
| T1057 Process Discovery |
MalwareEmotet | Emotet has been observed enumerating local processes. |
| T1057 Process Discovery |
MalwareCrimson | Crimson contains a command to list processes. |
| T1057 Process Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate running processes. |
| T1057 Process Discovery |
MalwareBADHATCH | BADHATCH can retrieve a list of running processes from a compromised machine. |
| T1057 Process Discovery |
MalwareMachete | Machete has a component to check for running processes to look for web browsers. |
| T1057 Process Discovery |
MalwareAvenger | Avenger has the ability to use Tasklist to identify running processes. |
| T1057 Process Discovery |
MalwarePUBLOAD | PUBLOAD has used `tasklist` to gather running processes on victim host. PUBLOAD has also leveraged the `OpenEventA` Windows API function to check whether the same process was already running. |
| T1057 Process Discovery |
MalwareSystemBC | SystemBC has the ability to enumerate running processes. |
| T1057 Process Discovery |
MalwareDacls | Dacls can collect data on running and parent processes. |
| T1057 Process Discovery |
MalwareWoody RAT | Woody RAT can call `NtQuerySystemProcessInformation` with `SystemProcessInformation` to enumerate all running processes, including associated information such as PID, parent PID, image name, and owner. |
| T1057 Process Discovery |
MalwareMafalda | Mafalda can enumerate running processes on a machine. |
| T1057 Process Discovery |
MalwareELMER | ELMER is capable of performing process listings. |
| T1057 Process Discovery |
MalwareShrinkLocker | ShrinkLocker checks whether the Bitlocker Drive Encryption Tools service is running. |
| T1057 Process Discovery |
MalwareSombRAT | SombRAT can use the |
| T1057 Process Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can use `ps aux` to enumerate running processes. |
| T1057 Process Discovery |
MalwareMobileOrder | MobileOrder has a command to upload information about all running processes to its C2 server. |
| T1057 Process Discovery |
MalwareInvisiMole | InvisiMole can obtain a list of running processes. |
| T1057 Process Discovery |
MalwareApostle | Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files. |
| T1057 Process Discovery |
MalwareVolgmer | Volgmer can gather a list of processes. |
| T1057 Process Discovery |
MalwareWINERACK | WINERACK can enumerate processes. |
| T1057 Process Discovery |
MalwareFruitFly | FruitFly has the ability to list processes on the system. |
| T1057 Process Discovery |
MalwareSkidmap | Skidmap has monitored critical processes to ensure resiliency. |
| T1057 Process Discovery |
MalwareBonadan | Bonadan can use the |
| T1057 Process Discovery |
MalwareConti | Conti can enumerate through all open processes to search for any that have the string “sql” in their process name. |
| T1057 Process Discovery |
MalwareRaspberry Robin | Raspberry Robin can identify processes running on the victim machine, such as security software, during execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.