Real-world descriptions of how a group, tool or campaign used a technique.
10 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1057 Process Discovery |
CampaignKV Botnet Activity | Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation. |
| T1057 Process Discovery |
CampaignFrankenstein | During Frankenstein, the threat actors used Empire to obtain a list of all running processes. |
| T1057 Process Discovery |
CampaignRedPenguin | During RedPenguin, UNC3886 used malware capable of reading the PID for the Junos OS snmpd daemon. |
| T1057 Process Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`. |
| T1057 Process Discovery |
CampaignC0015 | During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes. |
| T1057 Process Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes. |
| T1057 Process Discovery |
CampaignFunnyDream | During FunnyDream, the threat actors used Tasklist on targeted systems. |
| T1057 Process Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `tasklist` command as part of their advanced reconnaissance. |
| T1057 Process Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries enumerated current running processes using `tasklist`. |
| T1057 Process Discovery |
CampaignOperation Wocao | During Operation Wocao, the threat actors used `tasklist` to collect a list of running processes on an infected system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.