ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareCobalt Strike

Cobalt Strike's Beacon payload can collect information on process details.

T1057
Process Discovery
MalwareSUNBURST

SUNBURST collected a list of process names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists.

T1057
Process Discovery
MalwareEvilBunny

EvilBunny has used EnumProcesses() to identify how many process are running in the environment.

T1057
Process Discovery
MalwareHotCroissant

HotCroissant has the ability to list running processes on the infected host.

T1057
Process Discovery
MalwareValak

Valak has the ability to enumerate running processes on a compromised host.

T1057
Process Discovery
MalwareTaidoor

Taidoor can use GetCurrentProcessId for process discovery.

T1057
Process Discovery
MalwareCaddyWiper

CaddyWiper can obtain a list of current processes.

T1057
Process Discovery
MalwareCyclops Blink

Cyclops Blink can enumerate the process it is currently running under.

T1057
Process Discovery
MalwareSeasalt

Seasalt has a command to perform a process listing.

T1057
Process Discovery
MalwareTajMahal

TajMahal has the ability to identify running processes and associated plugins on an infected host.

T1057
Process Discovery
MalwarePLEAD

PLEAD has the ability to list processes on the compromised host.

T1057
Process Discovery
MalwareIPsec Helper

IPsec Helper can identify the process it is currently running under and its number, and pass this back to a command and control node.

T1057
Process Discovery
MalwareCarbon

Carbon can list the processes on the victim’s machine.

T1057
Process Discovery
MalwareTRAILBLAZE

TRAILBLAZE has conducted process discovery by searching for specific named processes such as `/home/bin/web`.

T1057
Process Discovery
MalwareCardinal RAT

Cardinal RAT contains watchdog functionality that ensures its process is always running, else spawns a new instance.

T1057
Process Discovery
MalwareBISCUIT

BISCUIT has a command to enumerate running processes and identify their owners.

T1057
Process Discovery
MalwareGold Dragon

Gold Dragon checks the running processes on the victim’s machine.

T1057
Process Discovery
MalwareRamsay

Ramsay can gather a list of running processes by using Tasklist.

T1057
Process Discovery
MalwareAshTag

The AshTag AshenOrchestrator component has process management functionality.

T1057
Process Discovery
MalwareCarberp

Carberp has collected a list of running processes.

T1057
Process Discovery
MalwareNKAbuse

NKAbuse will check victim systems to ensure only one copy of the malware is running.

T1057
Process Discovery
MalwarePillowmint

Pillowmint can iterate through running processes every six seconds collecting a list of processes to capture from later.

T1057
Process Discovery
MalwareMacMa

MacMa can enumerate running processes.

T1057
Process Discovery
MalwareFunnyDream

FunnyDream has the ability to discover processes, including `Bka.exe` and `BkavUtil.exe`.

T1057
Process Discovery
MalwareSUNSPOT

SUNSPOT monitored running processes for instances of MsBuild.exe by hashing the name of each running process and comparing it to the corresponding value 0x53D525. It also extracted command-line arguments and individual arguments from the running MsBuild.exe process to identify the directory path of the Orion software Visual Studio solution.

T1057
Process Discovery
MalwareSysUpdate

SysUpdate can collect information about running processes.

T1057
Process Discovery
MalwareOutSteel

OutSteel can identify running processes on a compromised host.

T1057
Process Discovery
MalwareKwampirs

Kwampirs collects a list of running services with the command tasklist /v.

T1057
Process Discovery
MalwareLAMEHUG

LAMEHUG can gather process information on targeted systems.

T1057
Process Discovery
MalwareLookBack

LookBack can list running processes.

T1057
Process Discovery
MalwareClop

Clop can enumerate all processes on the victim's machine.

T1057
Process Discovery
MalwarePoetRAT

PoetRAT has the ability to list all running processes.

T1057
Process Discovery
MalwareFELIXROOT

FELIXROOT collects a list of running processes.

T1057
Process Discovery
MalwareZxShell

ZxShell has a command, ps, to obtain a listing of processes on the system.

T1057
Process Discovery
MalwareSPAWNCHIMERA

SPAWNCHIMERA has searched for running processes to include web or dsmdm.

T1057
Process Discovery
MalwareBabyShark

BabyShark has executed the tasklist command.

T1057
Process Discovery
MalwareCannon

Cannon can obtain a list of processes running on the system.

T1057
Process Discovery
MalwareWinnti for Windows

Winnti for Windows can check if the explorer.exe process is responsible for calling its install function.

T1057
Process Discovery
MalwareBLACKCOFFEE

BLACKCOFFEE has the capability to discover processes.

T1057
Process Discovery
MalwareKinsing

Kinsing has used ps to list processes.

T1057
Process Discovery
MalwareMeteor

Meteor can check if a specific process is running, such as Kaspersky's `avp.exe`.

T1057
Process Discovery
MalwarenjRAT

njRAT can search a list of running processes for Tr.exe.

T1057
Process Discovery
MalwareZIPLINE

ZIPLINE can identify running processes and their names.

T1057
Process Discovery
MalwareMaze

Maze has gathered all of the running system processes.

T1057
Process Discovery
MalwareHIUPAN

HIUPAN has conducted process discovery to identify the PUBLOAD malware under the process WCBrowserWatcher.exe and will launch it from an install directory if it is not found.

T1057
Process Discovery
MalwareChChes

ChChes collects its process identifier (PID) on the victim.

T1057
Process Discovery
MalwarePowerStallion

PowerStallion has been used to monitor process lists.

T1057
Process Discovery
MalwareJPIN

JPIN can list running processes.

T1057
Process Discovery
MalwaremetaMain

metaMain can enumerate the processes that run on the platform.

T1057
Process Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor can gather process information.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.