Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
MalwareLunarWeb | LunarWeb has used shell commands to list running processes. |
| T1057 Process Discovery |
MalwareKillDisk | KillDisk has called |
| T1057 Process Discovery |
MalwareQilin | Qilin can define specific processes to be terminated or left alone at execution. |
| T1057 Process Discovery |
MalwareSoreFang | SoreFang can enumerate processes on a victim machine through use of Tasklist. |
| T1057 Process Discovery |
MalwareSocksbot | Socksbot can list all running processes. |
| T1057 Process Discovery |
MalwareAgent Tesla | Agent Tesla can list the current running processes on the system. |
| T1057 Process Discovery |
MalwarePasam | Pasam creates a backdoor through which remote attackers can retrieve lists of running processes. |
| T1057 Process Discovery |
MalwarePOWERSTATS | POWERSTATS has used |
| T1057 Process Discovery |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can retrieve a list of running processes. |
| T1057 Process Discovery |
MalwareGoopy | Goopy has checked for the Google Updater process to ensure Goopy was loaded properly. |
| T1057 Process Discovery |
MalwareShadowPad | ShadowPad has collected the PID of a malicious process. |
| T1057 Process Discovery |
MalwareAstaroth | Astaroth searches for different processes on the system. |
| T1057 Process Discovery |
MalwareQakBot | QakBot has the ability to check running processes. |
| T1057 Process Discovery |
MalwareSYSCON | SYSCON has the ability to use Tasklist to list running processes. |
| T1057 Process Discovery |
MalwareGelsemium | Gelsemium can enumerate running processes. |
| T1057 Process Discovery |
MalwarejRAT | jRAT can query and kill system processes. |
| T1057 Process Discovery |
MalwareHelminth | |
| T1057 Process Discovery |
MalwareKomplex | The OsInfo function in Komplex collects a running process list. |
| T1057 Process Discovery |
MalwareINC Ransomware | INC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt. |
| T1057 Process Discovery |
MalwareWaterbear | Waterbear can identify the process for a specific security product. |
| T1057 Process Discovery |
MalwareComnie | Comnie uses the |
| T1057 Process Discovery |
MalwareLizar | Lizar has a plugin designed to obtain a list of processes. |
| T1057 Process Discovery |
MalwareDtrack | Dtrack’s dropper can list all running processes. |
| T1057 Process Discovery |
MalwareLoudMiner | LoudMiner used the |
| T1057 Process Discovery |
MalwareAzorult | Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot. |
| T1057 Process Discovery |
MalwareBACKSPACE | BACKSPACE may collect information about running processes. |
| T1057 Process Discovery |
MalwareZox | Zox has the ability to list processes. |
| T1057 Process Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list running processes. |
| T1057 Process Discovery |
MalwareWarzoneRAT | WarzoneRAT can obtain a list of processes on a compromised host. |
| T1057 Process Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has enumerated processes by ID, name, or privileges. |
| T1057 Process Discovery |
ToolShimRatReporter | ShimRatReporter listed all running processes on the machine. |
| T1057 Process Discovery |
ToolSILENTTRINITY | SILENTTRINITY can enumerate processes, including properties to determine if they have the Common Language Runtime (CLR) loaded. |
| T1057 Process Discovery |
ToolPowerSploit | PowerSploit's |
| T1057 Process Discovery |
ToolTasklist | Tasklist can be used to discover processes running on a system. |
| T1057 Process Discovery |
ToolEmpire | Empire can find information about processes running on local and remote systems. |
| T1057 Process Discovery |
ToolPcShare | PcShare can obtain a list of running processes on a compromised host. |
| T1057 Process Discovery |
ToolAsyncRAT | AsyncRAT can examine running processes to determine if a debugger is present. |
| T1057 Process Discovery |
ToolBrute Ratel C4 | Brute Ratel C4 can enumerate all processes and locate specific process IDs (PIDs). |
| T1057 Process Discovery |
ToolRemcos | Remcos can discover running processes on compromised machines. |
| T1057 Process Discovery |
ToolImminent Monitor | Imminent Monitor has a "Process Watcher" feature to monitor processes in case the client ever crashes or gets closed. |
| T1057 Process Discovery |
ToolDonut | Donut includes subprojects that enumerate and identify information about Process Injection candidates. |
| T1057 Process Discovery |
ToolIronNetInjector | IronNetInjector can identify processes via C# methods such as |
| T1057 Process Discovery |
ToolPupy | Pupy can list the running processes and get the process ID and parent process’s ID. |
| T1057 Process Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can locate GitHub Actions runner processes. |
| T1057 Process Discovery |
MalwareDuqu | The discovery modules used with Duqu can collect information on process details. |
| T1059 Command and Scripting Interpreter |
CampaignOperation Spalax | For Operation Spalax, the threat actors used Nullsoft Scriptable Install System (NSIS) scripts to install malware. |
| T1059 Command and Scripting Interpreter |
CampaignCutting Edge | During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data. |
| T1059 Command and Scripting Interpreter |
CampaignArcaneDoor | ArcaneDoor included the adversary executing command line interface (CLI) commands. |
| T1059 Command and Scripting Interpreter |
CampaignFLORAHOX Activity | FLORAHOX Activity has executed PHP and Shell scripts to identify and infect subsequent routers for the ORB network. |
| T1059 Command and Scripting Interpreter |
GroupDragonfly | Dragonfly has used the command line for execution. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.