Technique.View on attack.mitre.org
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
In Windows environments, adversaries could obtain details on running processes using the Tasklist utility via cmd or Get-Process via PowerShell. Information about processes can also be extracted from the output of Native API calls such as CreateToolhelp32Snapshot. In Mac and Linux, this is accomplished with the ps command. Adversaries may also opt to enumerate processes via `/proc`. ESXi also supports use of the `ps` command, as well as `esxcli system process list`.
On network devices, Network Device CLI commands such as `show processes` can be used to display current running processes.
Rules on DetectionCode tagged with T1057.
| Rule | Level | Log source |
|---|---|---|
| HackTool - PCHunter Execution | high | windows / process_creation |
| Potential Process Reconnaissance via Wmic.EXE | medium | windows / process_creation |
| Recon Command Output Piped To Findstr.EXE | medium | windows / process_creation |
| Cisco Discovery | low | cisco / NULL |
| Suspicious Process Discovery With Get-Process | low | windows / ps_script |
| System Info Discovery via Sysinfo Syscall | low | linux / NULL |
| Process Discovery | informational | linux / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Windows Process Commandline Discovery | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAndariel | Andariel has used |
| GroupAPT1 | APT1 gathered a list of running processes on the system using |
| GroupAPT28 | An APT28 loader Trojan will enumerate the victim's processes searching for explorer.exe if its current process does not have necessary permissions. |
| GroupAPT3 | APT3 has a tool that can list out currently running processes. |
| GroupAPT37 | APT37's Freenki malware lists running processes using the Microsoft Windows API. |
| GroupAPT38 | APT38 leveraged Sysmon to understand the processes, services in the organization. |
| GroupAPT5 | APT5 has used Windows-based utilities to carry out tasks including tasklist.exe. |
| GroupChimera | Chimera has used |
| Used by | Procedure example |
|---|---|
| Malware4H RAT | 4H RAT has the capability to obtain a listing of running processes (including loaded modules). |
| MalwareADVSTORESHELL | ADVSTORESHELL can list running processes. |
| MalwareAgent Tesla | Agent Tesla can list the current running processes on the system. |
| MalwareAkira | Akira verifies the deletion of volume shadow copies by checking for the existence of the process ID related to the process created to delete these items. |
| MalwareApostle | Apostle retrieves a list of all running processes on a victim host, and stops all services containing the string "sql," likely to propagate ransomware activity to database files. |
| MalwareAppleSeed | AppleSeed can enumerate the current process on a compromised host. |
| MalwareAria-body | Aria-body has the ability to enumerate loaded modules for a process.. |
| MalwareAshTag | The AshTag AshenOrchestrator component has process management functionality. |
View all 268 software examples
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries enumerated current running processes using `tasklist`. |
| CampaignC0015 | During C0015, the threat actors used the `tasklist /s` command as well as `taskmanager` to obtain a list of running processes. |
| CampaignFrankenstein | During Frankenstein, the threat actors used Empire to obtain a list of all running processes. |
| CampaignFunnyDream | During FunnyDream, the threat actors used Tasklist on targeted systems. |
| CampaignKV Botnet Activity | Scripts associated with KV Botnet Activity initial deployment can identify processes related to security tools and other botnet families for follow-on disabling during installation. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `tasklist` command as part of their advanced reconnaissance. |
| CampaignOperation Honeybee | During Operation Honeybee, the threat actors obtained a list of running processes on a victim machine using `cmd /c tasklist > %temp%\temp.ini`. |
| CampaignOperation Wocao | During Operation Wocao, the threat actors used `tasklist` to collect a list of running processes on an infected system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.