Process Discovery T1057

Tactic: Discovery

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Events covered

6 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 37 rules share fields, values, and exclusions.

Fields filtered most (30 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name21eq 12, in 7, regex_match 3arp.exe, atbroker.exe, bginfo.exe, cat, egrep
host.os.type17eq 16, in 1
event.type16eq 16start
EventType13in 10, eq 3exec, exec_event, ProcessRollup2, fork, opened-file
CommandLine12contains 5, regex_match 5, is_not_null 1, match 1, wildcard 1(?i)((tracert)|(query)|(net\s+((localgroup)|(group)|(conf..., (?i)((netstat)|(netsh)|(schtasks)|(tasklist)|(driverquery..., (?i)((whoami)|(dir)|(hostname)|(hostname)|(systeminfo)|(i..., (?i)whoami|systeminfo|ipconfig|arp|nltest|dclist|domain_t..., get
process.args11in 6, wildcard 4, eq 3, starts_with 2, contains 1, is_not_null 1/proc/*/maps, [heap], [stack], *Win32_Process*, --bytes
EventID6eq 64688, 1, 4104
Image5ends_with 4, eq 1, is_not_null 1, starts_with 1, wildcard 1/atop, /bin/, /boot/, /dev/shm/, /htop
OriginalFileName5eq 5wmic.exe, net.exe, pchunter.exe, psservice.exe, sc.exe
dc_process_name4gt 41, 2
event.category4eq 4process, file
parent_process_name4eq 3, regex_match 1(?i)(powershell\.exe)|(cmd\.exe), acrobat.exe, acrord32.exe, eqnedt32.exe, excel.exe
process.args_count4eq 3, le 11, 2, 20, 3
ParentImage3is_not_null 2, eq 1?:\program files (x86)\teamcity\jre\bin\java.exe, ?:\program files\teamcity\jre\bin\java.exe, ?:\teamcity\buildagent\jre\bin\java.exe
ScriptBlockText2contains 1, eq 1, in 1.getgporeport(), ::getipglobalproperties(), ::getprocesses, get-process

Top indicator values (452 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
161087
EventTypein
exec
10206
EventTypein
exec_event
10150
EventTypein
ProcessRollup2
6118
EventTypein
start
6168
EventTypein
executed
498
EventTypein
process_started
483
process_nameeq
tasklist.exe
610
process_nameeq
net.exe
528
process_nameeq
qprocess.exe
58
process_nameeq
sc.exe
532
process_nameeq
wmic.exe
566
process_nameeq
arp.exe
49
process_nameeq
dsget.exe
48
process_nameeq
dsquery.exe
412
process_nameeq
gpresult.exe
47
process_nameeq
hostname.exe
47
process_nameeq
ipconfig.exe
410
process_nameeq
nbtstat.exe
49
process_nameeq
net1.exe
439
process_nameeq
netsh.exe
421
process_nameeq
netstat.exe
49
process_nameeq
nltest.exe
411
process_nameeq
ping.exe
410
process_nameeq
powershell.exe
4186
process_nameeq
quser.exe
410
process_nameeq
qwinsta.exe
49
process_nameeq
reg.exe
427
process_nameeq
systeminfo.exe
49
process_nameeq
tracert.exe
46

Exclusions (263 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLineregex_match
(?i)\x5cSplunkUniversalForwarder\x5c(etc|bin)\x5c
2
CurrentDirectorywildcard
/opt/Tanium/TaniumClient/*
2
ParentCommandLineeq
/sbin/init
2
ParentImageeq
/usr/lib/systemd/systemd
2
process.group_leader.executablein
/opt/traps/bin/cytool
2
process.group_leader.executablein
/usr/local/qualys/cloud-agent/bin/qualys-cloud-agent
2
process.parent.argsin
/sbin/chkrootkit
2
process.parent.argsin
/usr/sbin/chkrootkit
2
process_namein
netstat
2
process_namein
pidof
2
process_namein
ps
2
userregex_match
\$$
2
user.idin
S-1-5-18
2
user.idin
S-1-5-19
2
user.idin
S-1-5-20
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 8 rules

Elastic 21 rules

Splunk 6 rules

Kusto 2 rules