1200KM / simulation
T1057 Process Discovery — Attack Simulation
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary…
Technique description
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Discover Specific Process - tasklist
Procedure 11ba69ee-902e-4a0f-b3b6-418aed7d7ddb; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Process Discovery - Get-Process
Procedure 3b3809b6-a54b-4f5b-8aff-cb51f2e97b34; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Launch Taskmgr from cmd to View running processes
Procedure 4fd35378-39aa-481e-b7c4-e3bf49375c67; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Process Discovery - ps
Procedure 4ff64f0b-aaf2-4866-b39d-38d9791407cc; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Process Discovery - wmic process
Procedure 640cbf6d-659b-498b-ba53-f6dd1a1cc02c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Check Process Token Elevation via GetTokenInformation
Procedure 668f1d74-4bdb-4209-91e3-b31df0e4fbb7; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Process Discovery - Process Hacker
Procedure 966f4c16-1925-4d9b-8ce0-01334ee0867d; elevation required; cleanup not declared. Not executed or individually validated.
- Process Discovery - PC Hunter
Procedure b4ca838d-d013-4461-bf2c-f7132617b409; elevation required; cleanup not declared. Not executed or individually validated.
- Process Discovery - get-wmiObject
Procedure b51239b4-0129-474f-a2b4-70f855b9f2c2; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Process Discovery - tasklist
Procedure c5806a4f-62b8-4900-980b-c7ec004e9908; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT1 · G0006
- APT28 · G0007
- Deep Panda · G0009
- Turla · G0010
- Darkhotel · G0012
- Molerats · G0021
- APT3 · G0022
- Lazarus Group · G0032
- Poseidon Group · G0033
- Stealth Falcon · G0038
- Winnti Group · G0044
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- Magic Hound · G0059
- APT37 · G0067
- MuddyWater · G0069
- Tropic Trooper · G0081
- APT38 · G0082
- Kimsuky · G0094
- Inception · G0100
- Rocke · G0106
- Windshift · G0112
- Chimera · G0114
- Sidewinder · G0121
- HAFNIUM · G0125
- Higaisa · G0126
- Mustang Panda · G0129
- Andariel · G0138
- TeamTNT · G0139
- HEXANE · G1001
- Earth Lusca · G1006
- Volt Typhoon · G1017
- ToddyCat · G1022
- APT5 · G1023
- Play · G1040
- UNC3886 · G1048
- Medusa Group · G1051
- Storm-0501 · G1053
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.