# T1057 Process Discovery

> As of 2026-10-05, T1057 (Process Discovery) appears in 367 tracked threats, first reported 2021-11-25 and most recently 2026-10-03, with linked actors including APT38, Sapphire Sleet, Stardust Chollima; it most often appears alongside T1082 (System Information Discovery).

- **Tracked threats:** 367 (102 critical, 248 high, 17 medium)
- **First seen:** 2021-11-25
- **Last seen:** 2026-10-03
- **Threat actors:** 108
- **Detection rules:** 226 (counts only; Blue tier and above)

## Key facts

- **ID:** T1057
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1057/

## Activity timeline

T1057 first appeared in tracked threats on 2021-11-25 and was most recently reported on 2026-10-03. The busiest month was 2026-07 with 117 reports, and 366 of the 367 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1057 Process Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 367 of 2623 tracked threats (14%) to it; by severity that is 102 critical, 248 high, 17 medium.

Threats that use T1057 most often also use [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (300 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (261 threats), [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (216 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (207 threats), [T1140 Deobfuscate/Decode Files or Information](https://intel.threadlinqs.com/technique/T1140) (205 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

108 tracked threat actors appear in the threats that use T1057; the most frequent are [APT38](https://intel.threadlinqs.com/actor/APT38) (17), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (16), [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) (15), [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (9), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (8).

## Data sources

Telemetry that can reveal T1057, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [APT38](https://intel.threadlinqs.com/actor/APT38) — 17
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 16
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 15
- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 9
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 8
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 7
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 7
- [Kimsuky](https://intel.threadlinqs.com/actor/Kimsuky) — 7
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 6
- [Chaos](https://intel.threadlinqs.com/actor/Chaos) — 5
- [MuddyWater](https://intel.threadlinqs.com/actor/MuddyWater) — 5
- [Void Arachne](https://intel.threadlinqs.com/actor/Void%20Arachne) — 5

## Tracked threats

The 30 most recent of 367 tracked threats that use T1057.

- [BPFDoor, Rekoobe and AVERAT Linux Implants Impersonate SpamSniper and ShareTech Mail Security Appliances…](https://intel.threadlinqs.com/threat/TL-2026-2875) — high — 2026-10-03
- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [2CLoader: New Malware Loader Delivering Vidar, Remus and XWorm](https://intel.threadlinqs.com/threat/TL-2026-2819) — high — 2026-09-30
- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [CVE-2019-18935 Telerik UI Deserialization Exploited to Deploy Web Shells and a WordPress Scanner on IIS…](https://intel.threadlinqs.com/threat/TL-2026-2726) — critical — 2026-09-28
- [UTA0565 Chains Chrome and Windows Zero-Days (CVE-2026-85046, CVE-2026-87491, CVE-2026-85880) to Deploy…](https://intel.threadlinqs.com/threat/TL-2026-2681) — critical — 2026-09-27
- [BlueLocker Ransomware Resurfaces After Three-Year Dormancy, Breaches Pakistan Petroleum Limited](https://intel.threadlinqs.com/threat/TL-2026-2667) — high — 2026-09-26
- [Kothamine RAT Abuses Tailscale's Tailcat for Encrypted C2, Distributed via Malicious npm Packages](https://intel.threadlinqs.com/threat/TL-2026-2665) — high — 2026-09-26
- [Google Cloud Threat Intelligence: Supply Chain Compromise Campaigns and Mitigation Guidance (2025-2026)](https://intel.threadlinqs.com/threat/TL-2026-2657) — high — 2026-09-26
- [TokenGrabber: Python-based MaaS Infostealer Builder](https://intel.threadlinqs.com/threat/TL-2026-2643) — high — 2026-09-25
- [CLOSEDQUORUM: First Reported Autonomous AI-Driven C2 Implant Using LLM Plurality Voting (Windows Infostealer)](https://intel.threadlinqs.com/threat/TL-2026-2753) — medium — 2026-09-22
- [Lazarus Exploits CVE-2026-68820 Zero-Day via Malicious PDF Viewer in Operation Dream Job Against Defense…](https://intel.threadlinqs.com/threat/TL-2026-2561) — critical — 2026-09-18
- [Iranian State Actors Deploy CHOSEN BRICK Windows Malware to Spy on Dissidents, Activists, and Journalists](https://intel.threadlinqs.com/threat/TL-2026-2543) — high — 2026-09-16
- [Chosen Brick: Iranian State-Sponsored Windows Surveillance Malware Exposed by US, UK, and Dutch Agencies](https://intel.threadlinqs.com/threat/TL-2026-2534) — high — 2026-09-16
- [Rehub: Russian-Language Ransomware-as-a-Service Marketplace Absorbing RAMP's Displaced Operators](https://intel.threadlinqs.com/threat/TL-2026-2532) — medium — 2026-09-16
- [PhantomRaven: LLM-Generated npm Information Stealer Used for Bug Bounty Hunting](https://intel.threadlinqs.com/threat/TL-2026-2531) — high — 2026-09-16
- [Iranian MOIS-Linked Actor Uses Telegram-Controlled HEAVYGRAM/CHOSEN BRICK Malware Against Dissidents and…](https://intel.threadlinqs.com/threat/TL-2026-2526) — high — 2026-09-15
- [KREMLIN Banking Malware Hijacks Chrome and Edge via Phantom Extension/GhostChrome-X Integrity Bypass to…](https://intel.threadlinqs.com/threat/TL-2026-2525) — high — 2026-09-15
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [CVE-2026-51990: One-Click RCE in Tencent Sogou Input Method Exploited by UNC3569 to Deploy GrayRabbit Malware](https://intel.threadlinqs.com/threat/TL-2026-2474) — critical — 2026-09-13
- [Multi-Stage Cobalt Strike Loader Deploys Stageless Beacon via Anti-Sandbox .NET Chain](https://intel.threadlinqs.com/threat/TL-2026-2457) — high — 2026-09-12
- [ScarfaceStealer: Electron-Delivered Infostealer with Sandbox-Scoring Evasion and Smart-Contract C2](https://intel.threadlinqs.com/threat/TL-2026-2455) — high — 2026-09-12
- [SloppyRAT: New Remote Access Trojan Deployed via ClickFix in Ransomware-Linked Attacks](https://intel.threadlinqs.com/threat/TL-2026-2439) — high — 2026-09-10
- [CVE-2026-86218 — Unauthenticated Pre-Auth Remote Code Execution in N-able N-central (Active Exploitation…](https://intel.threadlinqs.com/threat/TL-2026-2415) — critical — 2026-09-09
- [PEEP: Chromium Toolkit Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution](https://intel.threadlinqs.com/threat/TL-2026-2380) — high — 2026-09-07
- [FalconFlank Zero-Day Local Privilege Escalation in CrowdStrike Falcon Sensor via Office Macro Remediation…](https://intel.threadlinqs.com/threat/TL-2026-2362) — high — 2026-09-06
- [StyleSmuggler — Magento Open Source and Adobe Commerce Unauthenticated RCE 0-Day Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2356) — critical — 2026-09-06
- [FalconFlank — CrowdStrike Falcon Sensor Local Privilege Escalation Zero-Day with Public PoC](https://intel.threadlinqs.com/threat/TL-2026-2350) — high — 2026-09-06
- [DPRK-Linked APT37 (Medium Confidence) Deploys Novel 'Ted' HAProxy Backdoor and 'CurlRAT'-Trojanized Linux…](https://intel.threadlinqs.com/threat/TL-2026-2329) — high — 2026-09-04
- [REVSTEALER Infostealer Campaign: Four C2-Delivered Modules Disable Windows Update & Defender to Deploy XMRig…](https://intel.threadlinqs.com/threat/TL-2026-2353) — high — 2026-09-02

## Related CVEs

CVEs referenced by the tracked threats that use T1057, most frequent first.

- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2017-0199](https://intel.threadlinqs.com/cve/CVE-2017-0199)
- [CVE-2021-26855](https://intel.threadlinqs.com/cve/CVE-2021-26855)
- [CVE-2021-31207](https://intel.threadlinqs.com/cve/CVE-2021-31207)
- [CVE-2021-34473](https://intel.threadlinqs.com/cve/CVE-2021-34473)
- [CVE-2021-34523](https://intel.threadlinqs.com/cve/CVE-2021-34523)
- [CVE-2021-4034](https://intel.threadlinqs.com/cve/CVE-2021-4034)
- [CVE-2022-40684](https://intel.threadlinqs.com/cve/CVE-2022-40684)
- [CVE-2022-41082](https://intel.threadlinqs.com/cve/CVE-2022-41082)
- [CVE-2023-38831](https://intel.threadlinqs.com/cve/CVE-2023-38831)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-49113](https://intel.threadlinqs.com/cve/CVE-2025-49113)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-18556](https://intel.threadlinqs.com/cve/CVE-2026-18556)
- [CVE-2026-18577](https://intel.threadlinqs.com/cve/CVE-2026-18577)
- [CVE-2026-33017](https://intel.threadlinqs.com/cve/CVE-2026-33017)
- [CVE-2026-3502](https://intel.threadlinqs.com/cve/CVE-2026-3502)
- [CVE-2026-60004](https://intel.threadlinqs.com/cve/CVE-2026-60004)
- [CVE-2026-68820](https://intel.threadlinqs.com/cve/CVE-2026-68820)
- [CVE-2026-86218](https://intel.threadlinqs.com/cve/CVE-2026-86218)
- [CVE-2014-8361](https://intel.threadlinqs.com/cve/CVE-2014-8361)

## Detection coverage

Threadlinqs maintains 226 detection rules mapped to T1057 (SPL 54, KQL 93, Sigma 79). Rule content is available to Blue tier accounts and above; this page shows counts only.

226 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1057
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
