41
Groups Using This
1
Tactics
5
Platforms
25
Prevalence Rank
Description

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. In Windows environments, adversaries could obtain details on running processes using the Tasklist utility via cmd or Get-Process via PowerShell. Information about processes can also be extracted from the output of Native API calls such as CreateToolhelp32Snapshot. In Mac and Linux, this is accomplished with the ps command. Adversaries may also opt to enumerate processes via `/proc`. ESXi also supports use of the `ps` command, as well as `esxcli system process list`. On network devices, Network Device CLI commands such as `show processes` can be used to display current running processes.

View MITRE record โ†—

Platforms
ESXiLinuxmacOSNetwork DevicesWindows
Groups Using T1057 (41)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0032
Lazarus Group
๐Ÿ‡ฐ๐Ÿ‡ต North Korea93 techniques26 software
G0007
APT28
๐Ÿ‡ท๐Ÿ‡บ Russia93 techniques29 software
G0129
Mustang Panda
๐Ÿ‡ท๐Ÿ‡บ Russia85 techniques23 software
G1017
Volt Typhoon
๐Ÿ‡จ๐Ÿ‡ณ China81 techniques17 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0047
Gamaredon Group
๐Ÿ‡ท๐Ÿ‡บ Russia70 techniques6 software
G0069
MuddyWater
๐Ÿ‡ฎ๐Ÿ‡ท Iran68 techniques21 software
G0010
Turla
๐Ÿ‡ท๐Ÿ‡บ Russia68 techniques30 software
G0046
FIN7
67 techniques19 software
G0114
Chimera
๐Ÿ‡จ๐Ÿ‡ณ China59 techniques6 software
G1051
Medusa Group
57 techniques5 software
G0082
APT38
๐Ÿ‡ฐ๐Ÿ‡ต North Korea56 techniques6 software
G0139
TeamTNT
56 techniques4 software
G1048
UNC3886
๐Ÿ‡จ๐Ÿ‡ณ China49 techniques8 software
G0004
Ke3chang
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques11 software
G1006
Earth Lusca
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques9 software
G0022
APT3
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G0125
HAFNIUM
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G1054
MirrorFace
๐Ÿ‡จ๐Ÿ‡ณ China43 techniques16 software
G1053
Storm-0501
42 techniques8 software
G0081
Tropic Trooper
40 techniques6 software
G0106
Rocke
๐Ÿ‡จ๐Ÿ‡ณ China36 techniques0 software
G1001
HEXANE
36 techniques12 software
G0121
Sidewinder
๐Ÿ‡จ๐Ÿ‡ณ China30 techniques1 software
G1023
APT5
๐Ÿ‡จ๐Ÿ‡ณ China29 techniques13 software
G0067
APT37
๐Ÿ‡ท๐Ÿ‡บ Russia29 techniques13 software
G0126
Higaisa
๐Ÿ‡ท๐Ÿ‡บ Russia28 techniques3 software
G1040
Play
26 techniques9 software
G1022
ToddyCat
25 techniques9 software
G0012
Darkhotel
๐Ÿ‡ฐ๐Ÿ‡ท South Korea24 techniques0 software
G0006
APT1
๐Ÿ‡จ๐Ÿ‡ณ China23 techniques17 software
G0100
Inception
๐Ÿ‡ท๐Ÿ‡บ Russia22 techniques3 software
G0112
Windshift
19 techniques1 software
G0038
Stealth Falcon
16 techniques0 software
G0021
Molerats
16 techniques6 software
G0138
Andariel
๐Ÿ‡ฐ๐Ÿ‡ต North Korea12 techniques2 software
G0009
Deep Panda
๐Ÿ‡จ๐Ÿ‡ณ China10 techniques7 software
G0033
Poseidon Group
8 techniques0 software
G0044
Winnti Group
๐Ÿ‡จ๐Ÿ‡ณ China6 techniques3 software
โ†‘