Detection Playbook: Process Discovery (T1057)
Process Discovery (T1057) is a reconnaissance technique where adversaries enumerate running processes on a compromised system to understand what software is …
Threat Intelligence for Every Defender
Daily MITRE ATT&CK-based detection playbooks covering common adversary techniques. Each playbook includes SIEM-agnostic detection logic and investigation and response guidance.
Process Discovery (T1057) is a reconnaissance technique where adversaries enumerate running processes on a compromised system to understand what software is …
System Owner/User Discovery (T1033) is a reconnaissance technique where adversaries enumerate the current user, active sessions, and account listings on a co…
System Network Configuration Discovery (T1016) is a technique where adversaries enumerate network settings on a compromised host — collecting IP addresses, M…
Disable Windows Event Logging (T1562.002) covers attacker actions that stop, corrupt, or suppress the Windows event logging pipeline — most commonly by tampe…
Disable or Modify Security Tools (T1562.001) describes attacker actions taken to impair, stop, or tamper with defensive software — including antivirus engine…
Clear Windows Event Logs (T1070.001) is a defense evasion technique where attackers delete or wipe Windows event log channels — such as Security, System, App…
Process injection (T1055) is a technique where adversaries insert and execute arbitrary code within the address space of a running, legitimate process. By hi…
Token Impersonation/Theft (T1134.001) is a Windows privilege escalation technique in which an adversary duplicates an existing access token belonging to anot…
DNS tunneling (T1071.004) is a command-and-control technique where adversaries embed data — including commands and exfiltrated output — inside DNS query and …
Web Protocols (T1071.001) describes adversaries using HTTP, HTTPS, and WebSocket as the transport layer for command-and-control (C2) communication. Rather th…