1200KM / detection
T1057 Process Discovery — Detection Rules
Detection workspace for T1057 Process Discovery: 6 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- System Info Discovery via Sysinfo Syscall · experimental · low · {"product":"linux","service":"auditd","definition":"Required auditd configuration:\n-a always,exit -F arch=b64 -S sysinfo -k discovery_sysinfo_syscall\n-a always,exit -F arch=b32 -S sysinfo -k discovery_sysinfo_syscall\n"}
- Cisco Discovery · test · low · {"product":"cisco","service":"aaa"}
- Suspicious Process Discovery With Get-Process · test · low · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Recon Command Output Piped To Findstr.EXE · test · medium · {"category":"process_creation","product":"windows"}
- HackTool - PCHunter Execution · test · high · {"category":"process_creation","product":"windows"}
- Potential Process Reconnaissance via Wmic.EXE · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1057 Process Discovery
MATCH(command_or_api IN process_enumeration_operations) AND caller NOT_IN approved_tools -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0034 Detection of Adversarial Process Discovery Behavior
AN0095 Analytic 0095
Identifies adversary behavior that launches commands or invokes APIs to enumerate active processes (e.g., tasklist.exe, Get-Process, or CreateToolhelp32Snapshot). Detects execution combined with parent process lineage, network session context, or remote origin.
AN0096 Analytic 0096
Detects execution of common process enumeration utilities (e.g., ps, top, htop) or access to /proc with suspicious ancestry. Correlates command usage with interactive shell context and user role.
AN0097 Analytic 0097
Monitors execution of ps, top, or launchctl with unusual parent processes or from terminal scripts. Also detects AppleScript-based process listing or `system_profiler SPApplicationsDataType` misuse.
AN0098 Analytic 0098
Detects process enumeration using `esxcli system process list` or `ps` on ESXi shell or via unauthorized SSH sessions. Correlates with interactive sessions and abnormal user roles.
AN0099 Analytic 0099
Monitors CLI-based execution of `show process` or equivalent on routers/switches. Correlates unusual device access, unauthorized roles, or config mode changes.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- APT28 · G0007
- Deep Panda · G0009
- Turla · G0010
- Darkhotel · G0012
- Molerats · G0021
- APT3 · G0022
- Lazarus Group · G0032
- Poseidon Group · G0033
- Stealth Falcon · G0038
- Winnti Group · G0044
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- Magic Hound · G0059
- APT37 · G0067
- MuddyWater · G0069
- Tropic Trooper · G0081
- APT38 · G0082
- Kimsuky · G0094
- Inception · G0100
- Rocke · G0106
- Windshift · G0112
- Chimera · G0114
- Sidewinder · G0121
- HAFNIUM · G0125
- Higaisa · G0126
- Mustang Panda · G0129
- Andariel · G0138
- TeamTNT · G0139
- HEXANE · G1001
- Earth Lusca · G1006
- Volt Typhoon · G1017
- ToddyCat · G1022
- APT5 · G1023
- Play · G1040
- UNC3886 · G1048
- Medusa Group · G1051
- Storm-0501 · G1053
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.