ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1057×

10 examples

TechniqueUsed byProcedure example
T1057
Process Discovery
CampaignKV Botnet Activity

Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation.

T1057
Process Discovery
CampaignFrankenstein

During Frankenstein, the threat actors used Empire to obtain a list of all running processes.

T1057
Process Discovery
CampaignRedPenguin

During RedPenguin, UNC3886 used malware capable of reading the PID for the Junos OS snmpd daemon.

T1057
Process Discovery
CampaignOperation Honeybee

During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`.

T1057
Process Discovery
CampaignC0015

During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes.

T1057
Process Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used multiple command-line utilities to enumerate running processes.

T1057
Process Discovery
CampaignFunnyDream

During FunnyDream, the threat actors used Tasklist on targeted systems.

T1057
Process Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `tasklist` command as part of their advanced reconnaissance.

T1057
Process Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries enumerated current running processes using `tasklist`.

T1057
Process Discovery
CampaignOperation Wocao

During Operation Wocao, the threat actors used `tasklist` to collect a list of running processes on an infected system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.