Tasklist

MITRE ATT&CK: S0057 View on attack.mitre.org

Aliases: Tasklist

Profile updated
2026-07-07 15:32:38

Context

The Tasklist utility displays a list of applications and services with their Process IDs (PID) for all tasks running on either a local or a remote computer. It is packaged with Windows operating systems and can be executed from the command-line interface.

Detection coverage

  • 21 Sigma rules

Malware & tools used

  • Process Discovery (attack-pattern)
  • System Service Discovery (attack-pattern)
  • Security Software Discovery (attack-pattern)

Used by threat actors

Reports & references

  • MITRE ATT&CK — S0057 (report)
  • Microsoft — Bb491010 (report)

External references