ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareMispadu

Mispadu can enumerate the running processes on a compromised host.

T1057
Process Discovery
MalwareMegazord

Megazord can terminate a list of specified services and processes.

T1057
Process Discovery
MalwareDiavol

Diavol has used `CreateToolhelp32Snapshot`, `Process32First`, and `Process32Next` API calls to enumerate the running processes in the system.

T1057
Process Discovery
MalwareDoki

Doki has searched for the current process’s PID.

T1057
Process Discovery
MalwareFysbis

Fysbis can collect information about running processes.

T1057
Process Discovery
MalwareVERMIN

VERMIN can get a list of the processes and running tasks on the system.

T1057
Process Discovery
MalwareUBoatRAT

UBoatRAT can list running processes on the system.

T1057
Process Discovery
MalwareNightdoor

Nightdoor can collect information on installed applications via Windows registry keys, as well as collecting information on running processes.

T1057
Process Discovery
MalwareMarkiRAT

MarkiRAT can search for different processes on a system.

T1057
Process Discovery
MalwarePowerShower

PowerShower has the ability to deploy a reconnaissance module to retrieve a list of the active processes.

T1057
Process Discovery
MalwareKazuar

Kazuar obtains a list of running processes through WMI querying and the ps command.

T1057
Process Discovery
MalwareNavRAT

NavRAT uses tasklist /v to check running processes.

T1057
Process Discovery
MalwareDarkComet

DarkComet can list active processes running on the victim’s machine.

T1057
Process Discovery
MalwareNETEAGLE

NETEAGLE can send process listings over the C2 channel.

T1057
Process Discovery
MalwarePOORAIM

POORAIM can enumerate processes.

T1057
Process Discovery
MalwareCHIMNEYSWEEP

CHIMNEYSWEEP can check if a process name contains “creensaver.”

T1057
Process Discovery
MalwareFatDuke

FatDuke can list running processes on the localhost.

T1057
Process Discovery
MalwareLucifer

Lucifer can identify the process that owns remote connections.

T1057
Process Discovery
MalwareBlackEnergy

BlackEnergy has gathered a process list by using Tasklist.exe.

T1057
Process Discovery
MalwareDRATzarus

DRATzarus can enumerate and examine running processes to determine if a debugger is present.

T1057
Process Discovery
MalwareRising Sun

Rising Sun can enumerate all running processes and process information on an infected machine.

T1057
Process Discovery
MalwareObliqueRAT

ObliqueRAT can check for blocklisted process names on a compromised host.

T1057
Process Discovery
MalwareSHOTPUT

SHOTPUT has a command to obtain a process listing.

T1057
Process Discovery
MalwareAvaddon

Avaddon has collected information about running processes.

T1057
Process Discovery
MalwareSocGholish

SocGholish can list processes on targeted hosts.

T1057
Process Discovery
MalwareFlagpro

Flagpro has been used to run the tasklist command on a compromised system.

T1057
Process Discovery
MalwareXAgentOSX

XAgentOSX contains the getProcessList function to run ps aux to get running processes.

T1057
Process Discovery
MalwareLightSpy

If sent the command `16002`, LightSpy uses the `NSWorkspace runningApplications()` method to collect the process ID, path to the executable, bundle information, and the filename of the executable for all running applications.

T1057
Process Discovery
MalwareHELLOKITTY

HELLOKITTY can search for specific processes to terminate.

T1057
Process Discovery
MalwareDarkTortilla

DarkTortilla can enumerate a list of running processes on a compromised system.

T1057
Process Discovery
MalwareROKRAT

ROKRAT can list the current running processes on the system.

T1057
Process Discovery
MalwareBabuk

Babuk has the ability to check running processes on a targeted system.

T1057
Process Discovery
MalwareJavali

Javali can monitor processes for open browsers and custom banking applications.

T1057
Process Discovery
MalwareBBSRAT

BBSRAT can list running processes.

T1057
Process Discovery
MalwarePlugX

PlugX has a module to list the processes running on a machine.

T1057
Process Discovery
MalwareBisonal

Bisonal can obtain a list of running processes on the victim’s machine.

T1057
Process Discovery
MalwareDustySky

DustySky collects information about running processes from victims.

T1057
Process Discovery
MalwareRemsec

Remsec can obtain a process list from the victim.

T1057
Process Discovery
MalwareIndustroyer2

Industroyer2 has the ability to cyclically enumerate running processes such as PServiceControl.exe, PService_PDD.exe, and other targets supplied through a hardcoded configuration.

T1057
Process Discovery
MalwareSykipot

Sykipot may gather a list of running processes by running tasklist /v.

T1057
Process Discovery
MalwareEpic

Epic uses the tasklist /v command to obtain a list of processes.

T1057
Process Discovery
MalwareCuba

Cuba can enumerate processes running on a victim's machine.

T1057
Process Discovery
MalwareClambling

Clambling can enumerate processes on a targeted system.

T1057
Process Discovery
MalwarePureCrypter

PureCrypter can enumerate processes on compromised hosts.

T1057
Process Discovery
MalwareAkira

Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items.

T1057
Process Discovery
MalwareDarkGate

DarkGate performs various checks for running processes, including security software by looking for hard-coded process name values.

T1057
Process Discovery
MalwareLockBit 3.0

LockBit 3.0 can identify and terminate specific services.

T1057
Process Discovery
MalwareSVCReady

SVCReady can collect a list of running processes from an infected host.

T1057
Process Discovery
MalwareThiefQuest

ThiefQuest obtains a list of running processes using the function kill_unwanted.

T1057
Process Discovery
MalwareFoggyWeb

FoggyWeb's loader can enumerate all Common Language Runtimes (CLRs) and running Application Domains in the compromised AD FS server's Microsoft.IdentityServer.ServiceHost.exe process.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.