ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1057×

41 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
GroupAPT38

APT38 leveraged Sysmon to understand the processes, services in the organization.

T1057
Process Discovery
GroupAPT3

APT3 has a tool that can list out currently running processes.

T1057
Process Discovery
GroupKimsuky

Kimsuky can gather a list of all processes running on a victim's machine. Kimsuky has also obtained running processes on the victim device utilizing PowerShell cmdlet `Get-Process`.

T1057
Process Discovery
GroupVolt Typhoon

Volt Typhoon has enumerated running processes on targeted systems including through the use of Tasklist.

T1057
Process Discovery
GroupHAFNIUM

HAFNIUM has used `tasklist` to enumerate processes.

T1057
Process Discovery
GroupMuddyWater

MuddyWater has used malware to obtain a list of running processes on the system.

T1057
Process Discovery
GroupGamaredon Group

Gamaredon Group has used tools to enumerate processes on target hosts including Process Explorer.

T1057
Process Discovery
GroupTeamTNT

TeamTNT has searched for rival malware and removes it if found. TeamTNT has also searched for running processes containing the strings aliyun or liyun to identify machines running Alibaba Cloud Security tools.

T1057
Process Discovery
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 to perform process discovery by executing `tasklist /v`. Additionally, WsTaskLoad.exe executes `tasklist /v` to perform process discovery.

T1057
Process Discovery
GroupAndariel

Andariel has used tasklist to enumerate processes and find a specific string.

T1057
Process Discovery
GroupSidewinder

Sidewinder has used tools to identify running processes on the victim's machine.

T1057
Process Discovery
GroupMustang Panda

Mustang Panda has used tasklist /v to determine active process information. Mustang Panda has also used TONESHELL malware to check the process name and process path to ensure it matches the expected one prior to triggering a custom exception handler.

T1057
Process Discovery
GroupRocke

Rocke can detect a running process's PID on the infected machine.

T1057
Process Discovery
GroupUNC3886

UNC3886 has run scripts to list all running processes on a guest VM from an ESXi host.

T1057
Process Discovery
GroupAPT37

APT37's Freenki malware lists running processes using the Microsoft Windows API.

T1057
Process Discovery
GroupOilRig

OilRig has run tasklist on a victim's machine and used infostealers to capture processes.

T1057
Process Discovery
GroupHigaisa

Higaisa’s shellcode attempted to find the process ID of the current process.

T1057
Process Discovery
GroupTropic Trooper

Tropic Trooper is capable of enumerating the running processes on the system using pslist.

T1057
Process Discovery
GroupKe3chang

Ke3chang performs process discovery using tasklist commands.

T1057
Process Discovery
GroupAPT1

APT1 gathered a list of running processes on the system using tasklist /v.

T1057
Process Discovery
GroupTurla

Turla surveys a system upon check-in to discover running processes using the tasklist /v command. Turla RPC backdoors have also enumerated processes associated with specific open ports or named pipes.

T1057
Process Discovery
GroupStorm-0501

Storm-0501 has discovered running processes through `tasklist.exe`.

T1057
Process Discovery
GroupPoseidon Group

After compromising a victim, Poseidon Group lists all running processes.

T1057
Process Discovery
GroupStealth Falcon

Stealth Falcon malware gathers a list of running processes.

T1057
Process Discovery
GroupChimera

Chimera has used tasklist to enumerate processes.

T1057
Process Discovery
GroupMirrorFace

MirrorFace has used Tasklist on compromised hosts for discovery.

T1057
Process Discovery
GroupMedusa Group

Medusa Group has utilized a hard-coded security tool process list that identifies and terminates using an undocumented IOCTL code 0x222094.

T1057
Process Discovery
GroupDarkhotel

Darkhotel malware can collect a list of running processes on a system.

T1057
Process Discovery
GroupDeep Panda

Deep Panda uses the Microsoft Tasklist utility to list processes running on systems.

T1057
Process Discovery
GroupWindshift

Windshift has used malware to enumerate active processes.

T1057
Process Discovery
GroupToddyCat

ToddyCat has run `cmd /c start /b tasklist` to enumerate processes.

T1057
Process Discovery
GroupAPT28

An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions.

T1057
Process Discovery
GroupAPT5

APT5 has used Windows-based utilities to carry out tasks including tasklist.exe.

T1057
Process Discovery
GroupWinnti Group

Winnti Group looked for a specific process running on infected servers.

T1057
Process Discovery
GroupLazarus Group

Several Lazarus Group malware families gather a list of running processes on a victim system and send it to their C2 server. A Destover-like variant used by Lazarus Group also gathers process times.

T1057
Process Discovery
GroupEarth Lusca

Earth Lusca has used Tasklist to obtain information from a compromised host.

T1057
Process Discovery
GroupMolerats

Molerats actors obtained a list of active processes on the victim and sent them to C2 servers.

T1057
Process Discovery
GroupInception

Inception has used a reconnaissance module to identify active processes and other associated loaded modules.

T1057
Process Discovery
GroupPlay

Play has used the information stealer Grixba to check for a list of security processes.

T1057
Process Discovery
GroupHEXANE

HEXANE has enumerated processes on targeted systems.

T1057
Process Discovery
GroupMagic Hound

Magic Hound malware can list running processes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.