Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareCarbanak | Carbanak lists running processes. |
| T1057 Process Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can monitor processes. |
| T1057 Process Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can gather a list of processes running on the machine. |
| T1057 Process Discovery |
MalwareElise | Elise enumerates processes via the |
| T1057 Process Discovery |
MalwareUSBferry | USBferry can use |
| T1057 Process Discovery |
MalwareTSCookie | TSCookie has the ability to list processes on the infected host. |
| T1057 Process Discovery |
MalwareLatrodectus | Latrodectus can enumerate running processes including process grandchildren on targeted hosts. |
| T1057 Process Discovery |
MalwareSaint Bot | Saint Bot has enumerated running processes on a compromised host to determine if it is running under the process name `dfrgui.exe`. |
| T1057 Process Discovery |
MalwareLODEINFO | LODEINFO can kill a process using specific process ID. |
| T1057 Process Discovery |
MalwareCharmPower | CharmPower has the ability to list running processes through the use of `tasklist`. |
| T1057 Process Discovery |
MalwareMuddyViper | MuddyViper has the ability to collect running processes. |
| T1057 Process Discovery |
MalwareBundlore | Bundlore has used the |
| T1057 Process Discovery |
MalwareP8RAT | P8RAT can check for specific processes associated with virtual environments. |
| T1057 Process Discovery |
MalwareSagerunex | Sagerunex identifies the `explorer.exe` process on the executing system. |
| T1057 Process Discovery |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can execute |
| T1057 Process Discovery |
MalwareLP-Notes | LP-Notes has searched for the process taskhostw.exe. |
| T1057 Process Discovery |
MalwareRoyal | Royal can use `GetCurrentProcess` to enumerate processes. |
| T1057 Process Discovery |
MalwareUroburos | Uroburos can use its `Process List` command to enumerate processes on compromised hosts. |
| T1057 Process Discovery |
MalwareMetamorfo | Metamorfo has performed process name checks and has monitored applications. |
| T1057 Process Discovery |
MalwareEmbargo | Embargo has utilized MS4Killer to detect running processes on the victim device. Embargo has also captured a snapshot of active running processes using the Windows API `CreateToolHelp32Snapshot()`. |
| T1057 Process Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can use Tasklist to collect a list of running tasks. |
| T1057 Process Discovery |
MalwarePipeMon | PipeMon can iterate over the running processes to find a suitable injection target. |
| T1057 Process Discovery |
MalwareKONNI | KONNI has used the command |
| T1057 Process Discovery |
Malwaregh0st RAT | gh0st RAT has the capability to list processes. |
| T1057 Process Discovery |
MalwareJHUHUGIT | JHUHUGIT obtains a list of running processes on the victim. |
| T1057 Process Discovery |
MalwareBLUELIGHT | BLUELIGHT can collect process filenames and SID authority level. |
| T1057 Process Discovery |
Malwaredown_new | down_new has the ability to list running processes on a compromised host. |
| T1057 Process Discovery |
MalwareIxeshe | Ixeshe can list running processes. |
| T1057 Process Discovery |
Malware4H RAT | 4H RAT has the capability to obtain a listing of running processes (including loaded modules). |
| T1057 Process Discovery |
MalwareRogueRobin | RogueRobin checks the running processes for evidence it may be running in a sandbox environment. It specifically enumerates processes for Wireshark and Sysinternals. |
| T1057 Process Discovery |
MalwareStreamEx | StreamEx has the ability to enumerate processes. |
| T1057 Process Discovery |
MalwareNightClub | NightClub has the ability to use `GetWindowThreadProcessId` to identify the process behind a specified window. |
| T1057 Process Discovery |
MalwareSDBbot | SDBbot can enumerate a list of running processes on a compromised machine. |
| T1057 Process Discovery |
MalwareMosquito | Mosquito runs |
| T1057 Process Discovery |
MalwareRTM | RTM can obtain information about process integrity levels. |
| T1057 Process Discovery |
MalwareDerusbi | Derusbi collects current and parent process IDs. |
| T1057 Process Discovery |
MalwareSodaMaster | SodaMaster can search a list of running processes. |
| T1057 Process Discovery |
MalwareGrandoreiro | Grandoreiro can identify installed security tools based on process names. |
| T1057 Process Discovery |
MalwareZxxZ | ZxxZ has created a snapshot of running processes using `CreateToolhelp32Snapshot`. |
| T1057 Process Discovery |
MalwareBazar | Bazar can identity the current process on a compromised host. |
| T1057 Process Discovery |
MalwareRATANKBA | RATANKBA lists the system’s processes. |
| T1057 Process Discovery |
MalwareMoonWind | MoonWind has a command to return a list of running processes. |
| T1057 Process Discovery |
MalwareHiddenFace | HiddenFace can check running processes against a list of blocklisted applications. |
| T1057 Process Discovery |
MalwareRyuk | Ryuk has called |
| T1057 Process Discovery |
MalwareFinal1stspy | Final1stspy obtains a list of running processes. |
| T1057 Process Discovery |
MalwareMgBot | MgBot includes a module for establishing a process watchdog for itself, identifying if the MgBot process is still running. |
| T1057 Process Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can determine if a running process has administrative privileges and terminate processes that interfere with encryption or exfiltration. |
| T1057 Process Discovery |
MalwareZebrocy | Zebrocy uses the |
| T1057 Process Discovery |
MalwarePandora | Pandora can monitor processes on a compromised host. |
| T1057 Process Discovery |
MalwareFinFisher | FinFisher checks its parent process for indications that it is running in a sandbox setup. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.