ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareCarbanak

Carbanak lists running processes.

T1057
Process Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can monitor processes.

T1057
Process Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can gather a list of processes running on the machine.

T1057
Process Discovery
MalwareElise

Elise enumerates processes via the tasklist command.

T1057
Process Discovery
MalwareUSBferry

USBferry can use tasklist to gather information about the process running on the infected system.

T1057
Process Discovery
MalwareTSCookie

TSCookie has the ability to list processes on the infected host.

T1057
Process Discovery
MalwareLatrodectus

Latrodectus can enumerate running processes including process grandchildren on targeted hosts.

T1057
Process Discovery
MalwareSaint Bot

Saint Bot has enumerated running processes on a compromised host to determine if it is running under the process name `dfrgui.exe`.

T1057
Process Discovery
MalwareLODEINFO

LODEINFO can kill a process using specific process ID.

T1057
Process Discovery
MalwareCharmPower

CharmPower has the ability to list running processes through the use of `tasklist`.

T1057
Process Discovery
MalwareMuddyViper

MuddyViper has the ability to collect running processes.

T1057
Process Discovery
MalwareBundlore

Bundlore has used the ps command to list processes.

T1057
Process Discovery
MalwareP8RAT

P8RAT can check for specific processes associated with virtual environments.

T1057
Process Discovery
MalwareSagerunex

Sagerunex identifies the `explorer.exe` process on the executing system.

T1057
Process Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can execute ProcessList for process discovery.

T1057
Process Discovery
MalwareLP-Notes

LP-Notes has searched for the process taskhostw.exe.

T1057
Process Discovery
MalwareRoyal

Royal can use `GetCurrentProcess` to enumerate processes.

T1057
Process Discovery
MalwareUroburos

Uroburos can use its `Process List` command to enumerate processes on compromised hosts.

T1057
Process Discovery
MalwareMetamorfo

Metamorfo has performed process name checks and has monitored applications.

T1057
Process Discovery
MalwareEmbargo

Embargo has utilized MS4Killer to detect running processes on the victim device. Embargo has also captured a snapshot of active running processes using the Windows API `CreateToolHelp32Snapshot()`.

T1057
Process Discovery
MalwareTrojan.Karagany

Trojan.Karagany can use Tasklist to collect a list of running tasks.

T1057
Process Discovery
MalwarePipeMon

PipeMon can iterate over the running processes to find a suitable injection target.

T1057
Process Discovery
MalwareKONNI

KONNI has used the command cmd /c tasklist to get a snapshot of the current processes on the target machine.

T1057
Process Discovery
Malwaregh0st RAT

gh0st RAT has the capability to list processes.

T1057
Process Discovery
MalwareJHUHUGIT

JHUHUGIT obtains a list of running processes on the victim.

T1057
Process Discovery
MalwareBLUELIGHT

BLUELIGHT can collect process filenames and SID authority level.

T1057
Process Discovery
Malwaredown_new

down_new has the ability to list running processes on a compromised host.

T1057
Process Discovery
MalwareIxeshe

Ixeshe can list running processes.

T1057
Process Discovery
Malware4H RAT

4H RAT has the capability to obtain a listing of running processes (including loaded modules).

T1057
Process Discovery
MalwareRogueRobin

RogueRobin checks the running processes for evidence it may be running in a sandbox environment. It specifically enumerates processes for Wireshark and Sysinternals.

T1057
Process Discovery
MalwareStreamEx

StreamEx has the ability to enumerate processes.

T1057
Process Discovery
MalwareNightClub

NightClub has the ability to use `GetWindowThreadProcessId` to identify the process behind a specified window.

T1057
Process Discovery
MalwareSDBbot

SDBbot can enumerate a list of running processes on a compromised machine.

T1057
Process Discovery
MalwareMosquito

Mosquito runs tasklist to obtain running processes.

T1057
Process Discovery
MalwareRTM

RTM can obtain information about process integrity levels.

T1057
Process Discovery
MalwareDerusbi

Derusbi collects current and parent process IDs.

T1057
Process Discovery
MalwareSodaMaster

SodaMaster can search a list of running processes.

T1057
Process Discovery
MalwareGrandoreiro

Grandoreiro can identify installed security tools based on process names.

T1057
Process Discovery
MalwareZxxZ

ZxxZ has created a snapshot of running processes using `CreateToolhelp32Snapshot`.

T1057
Process Discovery
MalwareBazar

Bazar can identity the current process on a compromised host.

T1057
Process Discovery
MalwareRATANKBA

RATANKBA lists the system’s processes.

T1057
Process Discovery
MalwareMoonWind

MoonWind has a command to return a list of running processes.

T1057
Process Discovery
MalwareHiddenFace

HiddenFace can check running processes against a list of blocklisted applications.

T1057
Process Discovery
MalwareRyuk

Ryuk has called CreateToolhelp32Snapshot to enumerate all running processes.

T1057
Process Discovery
MalwareFinal1stspy

Final1stspy obtains a list of running processes.

T1057
Process Discovery
MalwareMgBot

MgBot includes a module for establishing a process watchdog for itself, identifying if the MgBot process is still running.

T1057
Process Discovery
MalwareLockBit 2.0

LockBit 2.0 can determine if a running process has administrative privileges and terminate processes that interfere with encryption or exfiltration.

T1057
Process Discovery
MalwareZebrocy

Zebrocy uses the tasklist and wmic process get Capture, ExecutablePath commands to gather the processes running on the system.

T1057
Process Discovery
MalwarePandora

Pandora can monitor processes on a compromised host.

T1057
Process Discovery
MalwareFinFisher

FinFisher checks its parent process for indications that it is running in a sandbox setup.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.