What MITRE ATT&CK T1057: Process Discovery (Enterprise Tactic TA0007 - Discovery) requires
MITRE ATT&CK T1057 describes adversary enumeration of running processes to identify security tools, valuable applications, and post-exploitation opportunities. Common commands include tasklist, Get-Process, ps, and direct API calls. Process enumeration is typically followed by Impair Defenses (T1562) once security tools are identified. Compliance obligations include endpoint detection coverage (NIST 800-53 SI-3 and SI-4), command-line audit logging required by PCI DSS Req 10.2.1.7, and behavioural correlation analytics under DORA Article 9.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1057/
SHA-256 integrity: 18542897babb69fe2e2d12b0afbb0a323df7e5bba3eed0f72d61c03505c7908f
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1057: Process Discovery (https://attack.mitre.org/techniques/T1057/)
- NIST SP 800-53 Rev 5: SI-4 (Information System Monitoring), AU-2 (Event Logging)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
- Discovery (free): /api/v1/nodes/mitre-attack-t1057-process-discovery.json — 6-field metadata
- Vault (full node): /api/v1/vault/nodes/mitre-attack-t1057-process-discovery.json — full 13-key payload, $0.01 USDC (L402/Skyfire/Direct Base)
- Canonical URL: https://bidda.com/intelligence/mitre-attack-t1057-process-discovery
- Back to registry: Browse all 10,085 compliance nodes