Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareCobalt Strike | Cobalt Strike's Beacon payload can collect information on process details. |
| T1057 Process Discovery |
MalwareSUNBURST | SUNBURST collected a list of process names that were hashed using a FNV-1a + XOR algorithm to check against similarly-hashed hardcoded blocklists. |
| T1057 Process Discovery |
MalwareEvilBunny | EvilBunny has used EnumProcesses() to identify how many process are running in the environment. |
| T1057 Process Discovery |
MalwareHotCroissant | HotCroissant has the ability to list running processes on the infected host. |
| T1057 Process Discovery |
MalwareValak | Valak has the ability to enumerate running processes on a compromised host. |
| T1057 Process Discovery |
MalwareTaidoor | Taidoor can use |
| T1057 Process Discovery |
MalwareCaddyWiper | CaddyWiper can obtain a list of current processes. |
| T1057 Process Discovery |
MalwareCyclops Blink | Cyclops Blink can enumerate the process it is currently running under. |
| T1057 Process Discovery |
MalwareSeasalt | Seasalt has a command to perform a process listing. |
| T1057 Process Discovery |
MalwareTajMahal | TajMahal has the ability to identify running processes and associated plugins on an infected host. |
| T1057 Process Discovery |
MalwarePLEAD | PLEAD has the ability to list processes on the compromised host. |
| T1057 Process Discovery |
MalwareIPsec Helper | IPsec Helper can identify the process it is currently running under and its number, and pass this back to a command and control node. |
| T1057 Process Discovery |
MalwareCarbon | Carbon can list the processes on the victim’s machine. |
| T1057 Process Discovery |
MalwareTRAILBLAZE | TRAILBLAZE has conducted process discovery by searching for specific named processes such as `/home/bin/web`. |
| T1057 Process Discovery |
MalwareCardinal RAT | Cardinal RAT contains watchdog functionality that ensures its process is always running, else spawns a new instance. |
| T1057 Process Discovery |
MalwareBISCUIT | BISCUIT has a command to enumerate running processes and identify their owners. |
| T1057 Process Discovery |
MalwareGold Dragon | Gold Dragon checks the running processes on the victim’s machine. |
| T1057 Process Discovery |
MalwareRamsay | Ramsay can gather a list of running processes by using Tasklist. |
| T1057 Process Discovery |
MalwareAshTag | The AshTag AshenOrchestrator component has process management functionality. |
| T1057 Process Discovery |
MalwareCarberp | Carberp has collected a list of running processes. |
| T1057 Process Discovery |
MalwareNKAbuse | NKAbuse will check victim systems to ensure only one copy of the malware is running. |
| T1057 Process Discovery |
MalwarePillowmint | Pillowmint can iterate through running processes every six seconds collecting a list of processes to capture from later. |
| T1057 Process Discovery |
MalwareMacMa | MacMa can enumerate running processes. |
| T1057 Process Discovery |
MalwareFunnyDream | FunnyDream has the ability to discover processes, including `Bka.exe` and `BkavUtil.exe`. |
| T1057 Process Discovery |
MalwareSUNSPOT | SUNSPOT monitored running processes for instances of |
| T1057 Process Discovery |
MalwareSysUpdate | SysUpdate can collect information about running processes. |
| T1057 Process Discovery |
MalwareOutSteel | OutSteel can identify running processes on a compromised host. |
| T1057 Process Discovery |
MalwareKwampirs | Kwampirs collects a list of running services with the command |
| T1057 Process Discovery |
MalwareLAMEHUG | LAMEHUG can gather process information on targeted systems. |
| T1057 Process Discovery |
MalwareLookBack | LookBack can list running processes. |
| T1057 Process Discovery |
MalwareClop | Clop can enumerate all processes on the victim's machine. |
| T1057 Process Discovery |
MalwarePoetRAT | PoetRAT has the ability to list all running processes. |
| T1057 Process Discovery |
MalwareFELIXROOT | FELIXROOT collects a list of running processes. |
| T1057 Process Discovery |
MalwareZxShell | ZxShell has a command, ps, to obtain a listing of processes on the system. |
| T1057 Process Discovery |
MalwareSPAWNCHIMERA | SPAWNCHIMERA has searched for running processes to include web or dsmdm. |
| T1057 Process Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1057 Process Discovery |
MalwareCannon | Cannon can obtain a list of processes running on the system. |
| T1057 Process Discovery |
MalwareWinnti for Windows | Winnti for Windows can check if the explorer.exe process is responsible for calling its install function. |
| T1057 Process Discovery |
MalwareBLACKCOFFEE | BLACKCOFFEE has the capability to discover processes. |
| T1057 Process Discovery |
MalwareKinsing | Kinsing has used ps to list processes. |
| T1057 Process Discovery |
MalwareMeteor | Meteor can check if a specific process is running, such as Kaspersky's `avp.exe`. |
| T1057 Process Discovery |
MalwarenjRAT | njRAT can search a list of running processes for Tr.exe. |
| T1057 Process Discovery |
MalwareZIPLINE | ZIPLINE can identify running processes and their names. |
| T1057 Process Discovery |
MalwareMaze | Maze has gathered all of the running system processes. |
| T1057 Process Discovery |
MalwareHIUPAN | HIUPAN has conducted process discovery to identify the PUBLOAD malware under the process WCBrowserWatcher.exe and will launch it from an install directory if it is not found. |
| T1057 Process Discovery |
MalwareChChes | ChChes collects its process identifier (PID) on the victim. |
| T1057 Process Discovery |
MalwarePowerStallion | PowerStallion has been used to monitor process lists. |
| T1057 Process Discovery |
MalwareJPIN | JPIN can list running processes. |
| T1057 Process Discovery |
MalwaremetaMain | metaMain can enumerate the processes that run on the platform. |
| T1057 Process Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor can gather process information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.