Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareMispadu | Mispadu can enumerate the running processes on a compromised host. |
| T1057 Process Discovery |
MalwareMegazord | Megazord can terminate a list of specified services and processes. |
| T1057 Process Discovery |
MalwareDiavol | Diavol has used `CreateToolhelp32Snapshot`, `Process32First`, and `Process32Next` API calls to enumerate the running processes in the system. |
| T1057 Process Discovery |
MalwareDoki | Doki has searched for the current process’s PID. |
| T1057 Process Discovery |
MalwareFysbis | Fysbis can collect information about running processes. |
| T1057 Process Discovery |
MalwareVERMIN | VERMIN can get a list of the processes and running tasks on the system. |
| T1057 Process Discovery |
MalwareUBoatRAT | UBoatRAT can list running processes on the system. |
| T1057 Process Discovery |
MalwareNightdoor | Nightdoor can collect information on installed applications via Windows registry keys, as well as collecting information on running processes. |
| T1057 Process Discovery |
MalwareMarkiRAT | MarkiRAT can search for different processes on a system. |
| T1057 Process Discovery |
MalwarePowerShower | PowerShower has the ability to deploy a reconnaissance module to retrieve a list of the active processes. |
| T1057 Process Discovery |
MalwareKazuar | Kazuar obtains a list of running processes through WMI querying and the |
| T1057 Process Discovery |
MalwareNavRAT | NavRAT uses |
| T1057 Process Discovery |
MalwareDarkComet | DarkComet can list active processes running on the victim’s machine. |
| T1057 Process Discovery |
MalwareNETEAGLE | NETEAGLE can send process listings over the C2 channel. |
| T1057 Process Discovery |
MalwarePOORAIM | POORAIM can enumerate processes. |
| T1057 Process Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP can check if a process name contains “creensaver.” |
| T1057 Process Discovery |
MalwareFatDuke | FatDuke can list running processes on the localhost. |
| T1057 Process Discovery |
MalwareLucifer | Lucifer can identify the process that owns remote connections. |
| T1057 Process Discovery |
MalwareBlackEnergy | BlackEnergy has gathered a process list by using Tasklist.exe. |
| T1057 Process Discovery |
MalwareDRATzarus | DRATzarus can enumerate and examine running processes to determine if a debugger is present. |
| T1057 Process Discovery |
MalwareRising Sun | Rising Sun can enumerate all running processes and process information on an infected machine. |
| T1057 Process Discovery |
MalwareObliqueRAT | ObliqueRAT can check for blocklisted process names on a compromised host. |
| T1057 Process Discovery |
MalwareSHOTPUT | SHOTPUT has a command to obtain a process listing. |
| T1057 Process Discovery |
MalwareAvaddon | Avaddon has collected information about running processes. |
| T1057 Process Discovery |
MalwareSocGholish | SocGholish can list processes on targeted hosts. |
| T1057 Process Discovery |
MalwareFlagpro | Flagpro has been used to run the |
| T1057 Process Discovery |
MalwareXAgentOSX | XAgentOSX contains the getProcessList function to run |
| T1057 Process Discovery |
MalwareLightSpy | If sent the command `16002`, LightSpy uses the `NSWorkspace runningApplications()` method to collect the process ID, path to the executable, bundle information, and the filename of the executable for all running applications. |
| T1057 Process Discovery |
MalwareHELLOKITTY | HELLOKITTY can search for specific processes to terminate. |
| T1057 Process Discovery |
MalwareDarkTortilla | DarkTortilla can enumerate a list of running processes on a compromised system. |
| T1057 Process Discovery |
MalwareROKRAT | ROKRAT can list the current running processes on the system. |
| T1057 Process Discovery |
MalwareBabuk | Babuk has the ability to check running processes on a targeted system. |
| T1057 Process Discovery |
MalwareJavali | Javali can monitor processes for open browsers and custom banking applications. |
| T1057 Process Discovery |
MalwareBBSRAT | BBSRAT can list running processes. |
| T1057 Process Discovery |
MalwarePlugX | PlugX has a module to list the processes running on a machine. |
| T1057 Process Discovery |
MalwareBisonal | Bisonal can obtain a list of running processes on the victim’s machine. |
| T1057 Process Discovery |
MalwareDustySky | DustySky collects information about running processes from victims. |
| T1057 Process Discovery |
MalwareRemsec | Remsec can obtain a process list from the victim. |
| T1057 Process Discovery |
MalwareIndustroyer2 | Industroyer2 has the ability to cyclically enumerate running processes such as PServiceControl.exe, PService_PDD.exe, and other targets supplied through a hardcoded configuration. |
| T1057 Process Discovery |
MalwareSykipot | Sykipot may gather a list of running processes by running |
| T1057 Process Discovery |
MalwareEpic | Epic uses the |
| T1057 Process Discovery |
MalwareCuba | Cuba can enumerate processes running on a victim's machine. |
| T1057 Process Discovery |
MalwareClambling | Clambling can enumerate processes on a targeted system. |
| T1057 Process Discovery |
MalwarePureCrypter | PureCrypter can enumerate processes on compromised hosts. |
| T1057 Process Discovery |
MalwareAkira | Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items. |
| T1057 Process Discovery |
MalwareDarkGate | DarkGate performs various checks for running processes, including security software by looking for hard-coded process name values. |
| T1057 Process Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can identify and terminate specific services. |
| T1057 Process Discovery |
MalwareSVCReady | SVCReady can collect a list of running processes from an infected host. |
| T1057 Process Discovery |
MalwareThiefQuest | ThiefQuest obtains a list of running processes using the function |
| T1057 Process Discovery |
MalwareFoggyWeb | FoggyWeb's loader can enumerate all Common Language Runtimes (CLRs) and running Application Domains in the compromised AD FS server's |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.