T1057 Process Discovery in real malware
ATT&CK technique T1057 Process Discovery appears in 1529 publicly analyzed samples on MalwareAnalyzer by Cyble, 1.3% of the analyzed corpus. Seven-day prevalence is falling (1 recent vs 6 prior). Most associated families: HUILoader, Fugrafa, Emotet, Delf, Lmir.
Tactics: discovery
Prevalence in the corpus
- Samples exhibiting T1057: 1529
- Share of analyzed corpus: 1.3%
- Last 7 days: 1 · prior 7 days: 6 (falling)
Malware families using T1057
Example samples
- ADInsight64.exe - malicious
- Aurora15Connector.exe - malicious
- Aurora15Connector.exe - malicious
- Aurora15Connector.exe - malicious
- FB831A56_lock.exe - malicious
- Aurora15Connector.exe - malicious
- Advanced_IP_Scanner_2.5.4594.1.exe - suspicious
- 9768b7e31324805672cfcba91cf4d6da91494e9899db58f22da9dda6c91931d6.exe - malicious
- KeePass.exe - malicious
- 565ad987322dbf46b54562ca0eb53d5764228c4ee61e311315500beb8e7cec47 - malicious
- 1d241c1a63758f8aa1bffd5e05d9207889ac8ddc3649b5877d791ddd3aae28f4 - malicious
- 110fe3565eb6293c369e0e539499ae7d8217a6827278dcbabc62c61d6c78d122 - malicious
- 3e22901e7b039f8e5f0abf40183e598b61c97eae4c8e518c5053be9bea070fe3 - malicious
- c5c7032ed404dec1f9970a019167220ff011b4ce117e7e775262278ba900e195 - malicious
- af569ee985a279ead6234b61ce1957557eb573ae067d06d2c1ab77eda4c4f72d - malicious
- 59eb0ae37ec08651665874bcd99326b9d7f3a00e550948e7b8c3ed9142d4ec9c - malicious
- 46cfeb049ec1b54df89c49003c2b772750bbcd89e6ebb235bf1861771a6613a3 - malicious
- bae6157ecc8725f45770344bd174e6eef095660d3b89e042130bb154909e95ad - malicious
- 8d426aeabdb126c6af992785f00d1dbc176142905c4fa281bb2b6eb6b28b0fe3 - malicious
- cbe7e7925d3dddb228f61f1ebe6a9008cd14eb403a718330218d72dbfabb36e0 - malicious
- 0e5b7823bd4564ef25ad6bf8c9029a3e2eaec88ffe11ec6afe5bdc75c112360d - malicious
- f7c144fef9adbf0b13b0b2e949daad9c650c97db549a8ee984f59232ec80e933 - malicious
- 10cf4247d00a3d445328cbdede08796e5a7c3a42d27e9a7d3e562a68960ca1c0 - malicious
- 2512e5fe8931ef5018ed8dcabdbc11409085ec0cb0646ba0dcacccfe7001b1f1 - malicious
- 48724945d19df93be99ee36fa558472f08bd346fb1afd5ce8ace0ab8407f9c04 - malicious
Canonical technique definition: MITRE ATT&CK T1057 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1057
- How common is ATT&CK T1057 (Process Discovery) in real malware?
- ATT&CK technique T1057 Process Discovery appears in 1529 publicly analyzed samples on MalwareAnalyzer by Cyble, 1.3% of the analyzed corpus. Seven-day prevalence is falling (1 recent vs 6 prior). Most associated families: HUILoader, Fugrafa, Emotet, Delf, Lmir.
- Is T1057 becoming more common?
- Prevalence is falling: 1 sample in the last seven days against 6 in the seven days before. This measures submissions to MalwareAnalyzer by Cyble, so it reflects what is being submitted here rather than global attacker behaviour.
- Which malware families use T1057?
- In this corpus T1057 is most associated with HUILoader (128), Fugrafa (95), Emotet (67), Delf (55), Lmir (54). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1057?
- 1.3% of the publicly analyzed corpus (1529 of 114611 samples) exhibits T1057. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats