Tasklist
MITRE ATT&CK: S0057 View on attack.mitre.org
Aliases: Tasklist
- Profile updated
- 2026-07-07 15:32:38
Context
The Tasklist utility displays a list of applications and services with their Process IDs (PID) for all tasks running on either a local or a remote computer. It is packaged with Windows operating systems and can be executed from the command-line interface.
Detection coverage
- 21 Sigma rules
Malware & tools used
- Process Discovery (attack-pattern)
- System Service Discovery (attack-pattern)
- Security Software Discovery (attack-pattern)
Used by threat actors
- FunnyDream (campaign)
- Operation Honeybee (campaign)
- 2025 Poland Wiper Attacks (campaign)
- Threat Group-3390 (threat-actor)
- Deep Panda (threat-actor)
- Earth Lusca (threat-actor)
- Volt Typhoon (threat-actor)
- Storm-0501 (threat-actor)
- APT1 (threat-actor)
- Turla (threat-actor)
- Ke3chang (threat-actor)
- APT29 (threat-actor)
- Naikon (threat-actor)
- OilRig (threat-actor)
- APT5 (threat-actor)
- MirrorFace (threat-actor)
Reports & references
- MITRE ATT&CK — S0057 (report)
- Microsoft — Bb491010 (report)