Process Discovery

T1057

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

In Windows environments, adversaries could obtain details on running processes using the Tasklist utility via cmd or Get-Process via PowerShell. Information about processes can also be extracted from the output of Native API calls such as CreateToolhelp32Snapshot. In Mac and Linux, this is accomplished with the ps command. Adversaries may also opt to enumerate processes via `/proc`. ESXi also supports use of the `ps` command, as well as `esxcli system process list`.

On network devices, Network Device CLI commands such as `show processes` can be used to display current running processes.

Detection rules8

Rules on DetectionCode tagged with T1057.

Sigma7

RuleLevelLog source
HackTool - PCHunter Executionhighwindows / process_creation
Potential Process Reconnaissance via Wmic.EXEmediumwindows / process_creation
Recon Command Output Piped To Findstr.EXEmediumwindows / process_creation
Cisco Discoverylowcisco / NULL
Suspicious Process Discovery With Get-Processlowwindows / ps_script
System Info Discovery via Sysinfo Syscalllowlinux / NULL
Process Discoveryinformationallinux / process_creation

Splunk1

RuleTypeRiskData source
Windows Process Commandline DiscoveryHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups41

Show 17 more

Software268

Show 244 more
BisonalBLACKCOFFEEBlackEnergyBLUELIGHTBonadanBrave PrinceBRICKSTORMBrute Ratel C4BumblebeeBundloreCaddyWiperCannonCarbanakCarberpCarbonCardinal RATCaterpillar WebShellCharmPowerChChesCHIMNEYSWEEPClamblingClopCOATHANGERCobalt StrikeComnieContiCrimsonCubaCuckoo StealerCyclops BlinkDaclsDarkCometDarkGateDarkTortillaDerusbiDiavolDokiDonutdown_newDRATzarusDtrackDuquDUSTTRAPDustySkyEKANSEliseELMEREmbargoEmotetEmpireEpicEvilBunnyFatDukeFELIXROOTFinal1stspyFinFisherFlagproFoggyWebFrameworkPOSFruitFlyFunnyDreamFysbisGelsemiumGeminiDukeGet2gh0st RATGold DragonGoopyGrandoreiroGravityRATHALFBAKEDHavocHELLOKITTYHelminthHeyoka BackdoorHiddenFaceHIUPANHotCroissantHydraqiKittenImminent MonitorINC RansomwareIndustroyer2InvisibleFerretInvisiMoleIPsec HelperIronNetInjectorIxesheJavaliJHUHUGITJPINjRATKasidetKazuarKEYMARBLEKillDiskKinsingKomplexKONNIKOPILUWAKKwampirsLAMEHUGLatrodectusLightSpyLinfoLizarLockBit 2.0LockBit 3.0LODEINFOLookBackLoudMinerLP-NotesLuciferLunarWebMacheteMacMamacOS.OSAMinerMafaldaMarkiRATMazeMedusa RansomwareMegazordmetaMainMetamorfoMeteorMgBotMispaduMobileOrderMoonWindMosquitoMuddyViperNavRATNebulaeNETEAGLENETWIRENightClubNightdoorNinjanjRATNKAbuseObliqueRATOceanSaltOrzOutSteelP8RATPAKLOGPandoraPasamPcSharePillowmintPipeMonPLAINTEEPLEADPlugXPoetRATPOORAIMPowerDukePowerShowerPowerSploitPowerStallionPOWERSTATSPOWRUNERProxysvcPUBLOADPupyPureCrypterQakBotQilinRainyDayRamsayRansomHubRaspberry RobinRATANKBARCSessionRemcosRemsecRising SunRogueRobinROKRATRotaJakiroRoyalRTMRyukSagerunexSaint BotSardonicSDBbotSeasaltShadowPadShimRatReporterSHOTPUTShrinkLockerSILENTTRINITYSkidmapSLOTHFULMEDIASocGholishSocksbotSodaMasterSombRATSoreFangSPAWNCHIMERAStreamExStrongPitySUNBURSTSUNSPOTSVCReadySykipotSynAckSYSCONSystemBCSysUpdateTaidoorTAINTEDSCRIBETajMahalTasklistTeamPCP Cloud StealerThiefQuestTONESHELLTRAILBLAZETrickBotTrojan.KaraganyTSCookieUBoatRATUPSTYLEUroburosUrsnifUSBferryValakVERMINVolgmerWarzoneRATWaterbearWINERACKWinMMWinnti for WindowsWoody RATXAgentOSXytyZebrocyZeus PandaZIPLINEZoxZxShellZxxZ

Campaigns10

Procedure examples319

Groups41

Used byProcedure example
GroupAndariel

Andariel has used tasklist to enumerate processes and find a specific string.

GroupAPT1

APT1 gathered a list of running processes on the system using tasklist /v.

GroupAPT28

An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions.

GroupAPT3

APT3 has a tool that can list out currently running processes.

GroupAPT37

APT37's Freenki malware lists running processes using the Microsoft Windows API.

GroupAPT38

APT38 leveraged Sysmon to understand the processes, services in the organization.

GroupAPT5

APT5 has used Windows-based utilities to carry out tasks including tasklist.exe.

GroupChimera

Chimera has used tasklist to enumerate processes.

View all 41 groups examples

Software268

Used byProcedure example
Malware4H RAT

4H RAT has the capability to obtain a listing of running processes (including loaded modules).

MalwareADVSTORESHELL

ADVSTORESHELL can list running processes.

MalwareAgent Tesla

Agent Tesla can list the current running processes on the system.

MalwareAkira

Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items.

MalwareApostle

Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files.

MalwareAppleSeed

AppleSeed can enumerate the current process on a compromised host.

MalwareAria-body

Aria-body has the ability to enumerate loaded modules for a process..

MalwareAshTag

The AshTag AshenOrchestrator component has process management functionality.

View all 268 software examples

Campaigns10

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries enumerated current running processes using `tasklist`.

CampaignC0015

During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes.

CampaignFrankenstein

During Frankenstein, the threat actors used Empire to obtain a list of all running processes.

CampaignFunnyDream

During FunnyDream, the threat actors used Tasklist on targeted systems.

CampaignKV Botnet Activity

Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `tasklist` command as part of their advanced reconnaissance.

CampaignOperation Honeybee

During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`.

CampaignOperation Wocao

During Operation Wocao, the threat actors used `tasklist` to collect a list of running processes on an infected system.

View all 10 campaigns examples

References4

  1. Crowdstrike Hypervisor Jackpotting Pt 2 2021 Open source
    Michael Dawson. (2021, August 30). Hypervisor Jackpotting, Part 2: eCrime Actors Increase Targeting of ESXi Servers with Ransomware. Retrieved March 26, 2025.
  2. Sygnia ESXi Ransomware 2025 Open source
    Zhongyuan Hau (Aaron), Ren Jie Yow, and Yoav Mazor. (2025, January 21). ESXi Ransomware Attacks: Stealthy Persistence through. Retrieved March 27, 2025.
  3. US-CERT-TA18-106A Open source
    US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.
  4. show_processes_cisco_cmd Open source
    Cisco. (2022, August 16). show processes - . Retrieved July 13, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.