Process Discovery T1057

Tactic: Discovery

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Events covered

6 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 36 rules share fields, values, and exclusions.

Fields filtered most (30 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name20eq 12, in 6, regex_match 3arp.exe, atbroker.exe, bginfo.exe, egrep, (?i)(whoami|systeminfo|ipconfig|arp|nltest|tasklist|net1?...
host.os.type16eq 15, in 1
event.type15eq 15start
EventType12in 9, eq 3exec, exec_event, ProcessRollup2, fork, opened-file
CommandLine11contains 5, regex_match 5, is_not_null 1, match 1(?i)((tracert)|(query)|(net\s+((localgroup)|(group)|(conf..., (?i)((netstat)|(netsh)|(schtasks)|(tasklist)|(driverquery..., (?i)((whoami)|(dir)|(hostname)|(hostname)|(systeminfo)|(i..., (?i)whoami|systeminfo|ipconfig|arp|nltest|dclist|domain_t..., get
process.args11in 6, wildcard 4, eq 3, starts_with 2, contains 1, is_not_null 1/proc/*/maps, [heap], [stack], *Win32_Process*, --bytes
EventID6eq 64688, 1, 4104
Image5ends_with 4, eq 1, is_not_null 1, starts_with 1, wildcard 1/atop, /bin/, /boot/, /dev/shm/, /htop
OriginalFileName5eq 5wmic.exe, net.exe, pchunter.exe, psservice.exe, sc.exe
dc_process_name4gt 41, 2
event.category4eq 4process, file
parent_process_name4eq 3, regex_match 1(?i)(powershell\.exe)|(cmd\.exe), acrobat.exe, acrord32.exe, eqnedt32.exe, excel.exe
ParentImage3is_not_null 2, eq 1?:\program files (x86)\teamcity\jre\bin\java.exe, ?:\program files\teamcity\jre\bin\java.exe, ?:\teamcity\buildagent\jre\bin\java.exe
process.args_count3eq 31, 2, 3
ScriptBlockText2contains 1, eq 1, in 1.getgporeport(), ::getipglobalproperties(), ::getprocesses, get-process

Top indicator values (430 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
151078
EventTypein
exec
9201
EventTypein
exec_event
9149
EventTypein
ProcessRollup2
5117
EventTypein
start
5163
EventTypein
executed
498
EventTypein
process_started
483
process_nameeq
tasklist.exe
610
process_nameeq
net.exe
528
process_nameeq
qprocess.exe
58
process_nameeq
sc.exe
532
process_nameeq
wmic.exe
566
process_nameeq
arp.exe
49
process_nameeq
dsget.exe
48
process_nameeq
dsquery.exe
412
process_nameeq
gpresult.exe
47
process_nameeq
hostname.exe
47
process_nameeq
ipconfig.exe
410
process_nameeq
nbtstat.exe
49
process_nameeq
net1.exe
439
process_nameeq
netsh.exe
421
process_nameeq
netstat.exe
49
process_nameeq
nltest.exe
411
process_nameeq
ping.exe
410
process_nameeq
powershell.exe
4184
process_nameeq
quser.exe
410
process_nameeq
qwinsta.exe
49
process_nameeq
reg.exe
427
process_nameeq
systeminfo.exe
49
process_nameeq
tracert.exe
46

Exclusions (260 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLineregex_match
(?i)\x5cSplunkUniversalForwarder\x5c(etc|bin)\x5c
2
CurrentDirectorywildcard
/opt/Tanium/TaniumClient/*
2
process.parent.argsin
/sbin/chkrootkit
2
process.parent.argsin
/usr/sbin/chkrootkit
2
process_namein
netstat
2
process_namein
pidof
2
process_namein
ps
2
userregex_match
\$$
2
user.idin
S-1-5-18
2
user.idin
S-1-5-19
2
user.idin
S-1-5-20
2
CommandLinecontains
\catalina_start.bat
1
CommandLinecontains
\xampp\
1
CommandLinecontains
call
1
CommandLinecontains
cmd.exe /c tasklist /v |
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 8 rules

Elastic 20 rules

Splunk 6 rules

Kusto 2 rules