ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
MalwareLunarWeb

LunarWeb has used shell commands to list running processes.

T1057
Process Discovery
MalwareKillDisk

KillDisk has called GetCurrentProcess.

T1057
Process Discovery
MalwareQilin

Qilin can define specific processes to be terminated or left alone at execution.

T1057
Process Discovery
MalwareSoreFang

SoreFang can enumerate processes on a victim machine through use of Tasklist.

T1057
Process Discovery
MalwareSocksbot

Socksbot can list all running processes.

T1057
Process Discovery
MalwareAgent Tesla

Agent Tesla can list the current running processes on the system.

T1057
Process Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve lists of running processes.

T1057
Process Discovery
MalwarePOWERSTATS

POWERSTATS has used get_tasklist to discover processes on the compromised host.

T1057
Process Discovery
MalwareLinfo

Linfo creates a backdoor through which remote attackers can retrieve a list of running processes.

T1057
Process Discovery
MalwareGoopy

Goopy has checked for the Google Updater process to ensure Goopy was loaded properly.

T1057
Process Discovery
MalwareShadowPad

ShadowPad has collected the PID of a malicious process.

T1057
Process Discovery
MalwareAstaroth

Astaroth searches for different processes on the system.

T1057
Process Discovery
MalwareQakBot

QakBot has the ability to check running processes.

T1057
Process Discovery
MalwareSYSCON

SYSCON has the ability to use Tasklist to list running processes.

T1057
Process Discovery
MalwareGelsemium

Gelsemium can enumerate running processes.

T1057
Process Discovery
MalwarejRAT

jRAT can query and kill system processes.

T1057
Process Discovery
MalwareHelminth

Helminth has used Tasklist to get information on processes.

T1057
Process Discovery
MalwareKomplex

The OsInfo function in Komplex collects a running process list.

T1057
Process Discovery
MalwareINC Ransomware

INC Ransomware can use the Microsoft Win32 Restart Manager to kill processes with a specific handle or that are accessing resources it wants to encrypt.

T1057
Process Discovery
MalwareWaterbear

Waterbear can identify the process for a specific security product.

T1057
Process Discovery
MalwareComnie

Comnie uses the tasklist to view running processes on the victim’s machine.

T1057
Process Discovery
MalwareLizar

Lizar has a plugin designed to obtain a list of processes.

T1057
Process Discovery
MalwareDtrack

Dtrack’s dropper can list all running processes.

T1057
Process Discovery
MalwareLoudMiner

LoudMiner used the ps command to monitor the running processes on the system.

T1057
Process Discovery
MalwareAzorult

Azorult can collect a list of running processes by calling CreateToolhelp32Snapshot.

T1057
Process Discovery
MalwareBACKSPACE

BACKSPACE may collect information about running processes.

T1057
Process Discovery
MalwareZox

Zox has the ability to list processes.

T1057
Process Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list running processes.

T1057
Process Discovery
MalwareWarzoneRAT

WarzoneRAT can obtain a list of processes on a compromised host.

T1057
Process Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has enumerated processes by ID, name, or privileges.

T1057
Process Discovery
ToolShimRatReporter

ShimRatReporter listed all running processes on the machine.

T1057
Process Discovery
ToolSILENTTRINITY

SILENTTRINITY can enumerate processes, including properties to determine if they have the Common Language Runtime (CLR) loaded.

T1057
Process Discovery
ToolPowerSploit

PowerSploit's Get-ProcessTokenPrivilege Privesc-PowerUp module can enumerate privileges for a given process.

T1057
Process Discovery
ToolTasklist

Tasklist can be used to discover processes running on a system.

T1057
Process Discovery
ToolEmpire

Empire can find information about processes running on local and remote systems.

T1057
Process Discovery
ToolPcShare

PcShare can obtain a list of running processes on a compromised host.

T1057
Process Discovery
ToolAsyncRAT

AsyncRAT can examine running processes to determine if a debugger is present.

T1057
Process Discovery
ToolBrute Ratel C4

Brute Ratel C4 can enumerate all processes and locate specific process IDs (PIDs).

T1057
Process Discovery
ToolRemcos

Remcos can discover running processes on compromised machines.

T1057
Process Discovery
ToolImminent Monitor

Imminent Monitor has a "Process Watcher" feature to monitor processes in case the client ever crashes or gets closed.

T1057
Process Discovery
ToolDonut

Donut includes subprojects that enumerate and identify information about Process Injection candidates.

T1057
Process Discovery
ToolIronNetInjector

IronNetInjector can identify processes via C# methods such as GetProcessesByName and running Tasklist with the Python os.popen function.

T1057
Process Discovery
ToolPupy

Pupy can list the running processes and get the process ID and parent process’s ID.

T1057
Process Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can locate GitHub Actions runner processes.

T1057
Process Discovery
MalwareDuqu

The discovery modules used with Duqu can collect information on process details.

T1059
Command and Scripting Interpreter
CampaignOperation Spalax

For Operation Spalax, the threat actors used Nullsoft Scriptable Install System (NSIS) scripts to install malware.

T1059
Command and Scripting Interpreter
CampaignCutting Edge

During Cutting Edge, threat actors used Perl scripts to enable the deployment of the THINSPOOL shell script dropper and for enumerating host data.

T1059
Command and Scripting Interpreter
CampaignArcaneDoor

ArcaneDoor included the adversary executing command line interface (CLI) commands.

T1059
Command and Scripting Interpreter
CampaignFLORAHOX Activity

FLORAHOX Activity has executed PHP and Shell scripts to identify and infect subsequent routers for the ORB network.

T1059
Command and Scripting Interpreter
GroupDragonfly

Dragonfly has used the command line for execution.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.