MITRE ATT&CK CoA - T1057 - Process Discovery
This playbook Remediates the Process Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. ***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Techniques Handled: - T1057: Process Discovery Kill Chain phases: - Discovery MITRE ATT&CK Description: Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Possible playbook uses: - The playbook can be used independently to handle and remediate the specific technique. - The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK - Courses of Action · 8 tasks · 0 inputs · 1 output
Details
| ID | MITRE ATT&CK CoA - T1057 - Process Discovery |
|---|---|
| From Version | 6.5.0 |
| Tasks | 8 |
README
This playbook Remediates the Process Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1057: Process Discovery
Kill Chain phases:
- Discovery
MITRE ATT&CK Description:
Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
This playbook does not use any sub-playbooks.
Integrations
This playbook does not use any integrations.
Scripts
- IsIntegrationAvailable
- Set
- SetGridField
Commands
This playbook does not use any commands.
Playbook Inputs
There are no inputs for this playbook.
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| Handled.Techniques | The techniques handled in this playbook | unknown |
Playbook Image

Outputs
Handled.Techniques— The techniques handled in this playbook
Flowchart
description: "This playbook Remediates the Process Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.\n \n***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\nTechniques Handled:\n- T1057: Process Discovery\n\nKill Chain phases:\n- Discovery\n\nMITRE ATT&CK Description:\n\nAdversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nPossible playbook uses:\n- The playbook can be used independently to handle and remediate the specific technique.\n- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input." id: MITRE ATT&CK CoA - T1057 - Process Discovery inputs: [] name: MITRE ATT&CK CoA - T1057 - Process Discovery outputs: - contextPath: Handled.Techniques description: The techniques handled in this playbook type: unknown starttaskid: "0" tasks: "0": id: "0" ignoreworker: false nexttasks: '#none#': - "5" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 8e60441a-86eb-4c0b-84f4-3bde2619a537 iscommand: false name: "" version: -1 description: '' taskid: 8e60441a-86eb-4c0b-84f4-3bde2619a537 timertriggers: [] type: start view: |- { "position": { "x": 265, "y": -110 } } "1": id: "1" ignoreworker: false nexttasks: '#none#': - "6" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" description: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors. id: 3f6e55d4-9036-473a-8222-d175d8303d44 iscommand: false name: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors type: regular version: -1 taskid: 3f6e55d4-9036-473a-8222-d175d8303d44 timertriggers: [] type: regular view: |- { "position": { "x": 265, "y": 540 } } "2": id: "2" ignoreworker: false note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: f0044a7f-a9ba-485e-8dc7-6f5589920c0a iscommand: false name: Done type: title version: -1 description: '' taskid: f0044a7f-a9ba-485e-8dc7-6f5589920c0a timertriggers: [] type: title view: |- { "position": { "x": 265, "y": 1075 } } "3": id: "3" ignoreworker: false nexttasks: '#default#': - "4" "yes": - "1" note: false quietmode: 0 scriptarguments: brandname: simple: Cortex XDR - IR separatecontext: false skipunavailable: false task: brand: "" description: Returns 'yes' if integration brand is available. Otherwise returns 'no' id: 423e30aa-9b91-422d-8e78-625a86b54b17 iscommand: false name: Is Cortex XDR integration Enabled? script: IsIntegrationAvailable type: condition version: -1 taskid: 423e30aa-9b91-422d-8e78-625a86b54b17 timertriggers: [] type: condition view: |- { "position": { "x": 265, "y": 195 } } "4": id: "4" ignoreworker: false nexttasks: '#none#': - "1" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" description: | Enable the Cortex XDR integration to follow this CoA. If needed - please contact your Palo Alto Networks account manager for future guidance and assistance. id: 41184bd3-4ea5-4c0f-8990-f6b1bcaf2edc iscommand: false name: Manual - Enable Cortex XDR integration type: regular version: -1 taskid: 41184bd3-4ea5-4c0f-8990-f6b1bcaf2edc timertriggers: [] type: regular view: |- { "position": { "x": 520, "y": 370 } } "5": id: "5" ignoreworker: false nexttasks: '#none#': - "3" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 582019ae-12f5-4b29-823b-a79ef3543d00 iscommand: false name: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors type: title version: -1 description: '' taskid: 582019ae-12f5-4b29-823b-a79ef3543d00 timertriggers: [] type: title view: |- { "position": { "x": 265, "y": 50 } } "6": id: "6" ignoreworker: false nexttasks: '#none#': - "7" note: false quietmode: 0 scriptarguments: append: simple: "true" key: simple: Handled.Techniques stringify: {} value: simple: T1057 separatecontext: false skipunavailable: false task: brand: "" description: Set a value in context under the key you entered. id: dbe7e7b0-413d-447c-88ab-ee40819ac2e8 iscommand: false name: Set technique handled script: Set type: regular version: -1 taskid: dbe7e7b0-413d-447c-88ab-ee40819ac2e8 timertriggers: [] type: regular view: |- { "position": { "x": 265, "y": 720 } } "7": continueonerror: true id: "7" ignoreworker: false nexttasks: '#none#': - "2" note: false quietmode: 0 scriptarguments: columns: simple: technique context_path: simple: Handled.Techniques grid_id: simple: handledtechniques keys: {} overwrite: {} sort_by: {} unpack_nested_elements: {} separatecontext: false skipunavailable: false task: brand: "" description: Creates a Grid table from items or key-value pairs. id: 31158019-998a-4fb2-8474-c05946f0bc77 iscommand: false name: Set grid field script: SetGridField type: regular version: -1 taskid: 31158019-998a-4fb2-8474-c05946f0bc77 timertriggers: [] type: regular view: |- { "position": { "x": 265, "y": 900 } } version: -1 view: |- { "linkLabelsPosition": { "3_1_yes": 0.41 }, "paper": { "dimensions": { "height": 1250, "width": 635, "x": 265, "y": -110 } } } tests: - No tests (auto formatted) fromversion: 6.5.0