ATT&CK 기법 · Discovery
Process Discovery T1057
이 기법을 다룬 REVELARE 한국어 위협 분석 3편 · Discovery
이 기법을 다룬 분석
MITRE 공식 정의
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Administrator or otherwise elevated access may provide better process details. Adversaries may use the information from [Process Discovery](https://attack.mitre.org/techniques/T1057) during automated discovery to shape follow-on behaviors, including whether or not the …
플랫폼: ESXi, Linux, macOS, Network Devices, Windows