MITRE ATT&CK CoA - T1057 - Process Discovery

This playbook Remediates the Process Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. ***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Techniques Handled: - T1057: Process Discovery Kill Chain phases: - Discovery MITRE ATT&CK Description: Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Possible playbook uses: - The playbook can be used independently to handle and remediate the specific technique. - The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

MITRE ATT&CK - Courses of Action · 8 tasks · 0 inputs · 1 output

Details

IDMITRE ATT&CK CoA - T1057 - Process Discovery
From Version6.5.0
Tasks8

README

This playbook Remediates the Process Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.

***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:

  • T1057: Process Discovery

Kill Chain phases:

  • Discovery

MITRE ATT&CK Description:

Adversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Possible playbook uses:

  • The playbook can be used independently to handle and remediate the specific technique.
  • The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
  • The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

This playbook does not use any sub-playbooks.

Integrations

This playbook does not use any integrations.

Scripts

  • IsIntegrationAvailable
  • Set
  • SetGridField

Commands

This playbook does not use any commands.

Playbook Inputs


There are no inputs for this playbook.

Playbook Outputs


Path Description Type
Handled.Techniques The techniques handled in this playbook unknown

Playbook Image


MITRE ATT&CK CoA - T1057 - Process Discovery

Outputs

  • Handled.Techniques — The techniques handled in this playbook

Flowchart

yes Start Start Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors Cortex XDR monitors for b... Done Done Is Cortex XDR integration Enabled? Is Cortex XDR integration... Manual - Enable Cortex XDR integration Manual - Enable Cortex XD... Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors Cortex XDR monitors for b... Set technique handled Set technique handled Set grid field Set grid field
description: "This playbook Remediates the Process Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.\n \n***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\nTechniques Handled:\n- T1057: Process Discovery\n\nKill Chain phases:\n- Discovery\n\nMITRE ATT&CK Description:\n\nAdversaries may attempt to get information about running processes on a system. Information obtained could be used to gain an understanding of common software/applications running on systems within the network. Adversaries may use the information from Process Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nPossible playbook uses:\n- The playbook can be used independently to handle and remediate the specific technique.\n- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input."
id: MITRE ATT&CK CoA - T1057 - Process Discovery
inputs: []
name: MITRE ATT&CK CoA - T1057 - Process Discovery
outputs:
- contextPath: Handled.Techniques
  description: The techniques handled in this playbook
  type: unknown
starttaskid: "0"
tasks:
  "0":
    id: "0"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "5"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 8e60441a-86eb-4c0b-84f4-3bde2619a537
      iscommand: false
      name: ""
      version: -1
      description: ''
    taskid: 8e60441a-86eb-4c0b-84f4-3bde2619a537
    timertriggers: []
    type: start
    view: |-
      {
        "position": {
          "x": 265,
          "y": -110
        }
      }
  "1":
    id: "1"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "6"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors.
      id: 3f6e55d4-9036-473a-8222-d175d8303d44
      iscommand: false
      name: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors
      type: regular
      version: -1
    taskid: 3f6e55d4-9036-473a-8222-d175d8303d44
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 265,
          "y": 540
        }
      }
  "2":
    id: "2"
    ignoreworker: false
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: f0044a7f-a9ba-485e-8dc7-6f5589920c0a
      iscommand: false
      name: Done
      type: title
      version: -1
      description: ''
    taskid: f0044a7f-a9ba-485e-8dc7-6f5589920c0a
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 265,
          "y": 1075
        }
      }
  "3":
    id: "3"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "4"
      "yes":
      - "1"
    note: false
    quietmode: 0
    scriptarguments:
      brandname:
        simple: Cortex XDR - IR
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Returns 'yes' if integration brand is available. Otherwise returns 'no'
      id: 423e30aa-9b91-422d-8e78-625a86b54b17
      iscommand: false
      name: Is Cortex XDR integration Enabled?
      script: IsIntegrationAvailable
      type: condition
      version: -1
    taskid: 423e30aa-9b91-422d-8e78-625a86b54b17
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 265,
          "y": 195
        }
      }
  "4":
    id: "4"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "1"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: |
        Enable the Cortex XDR integration to follow this CoA.

        If needed - please contact your Palo Alto Networks account manager for future guidance and assistance.
      id: 41184bd3-4ea5-4c0f-8990-f6b1bcaf2edc
      iscommand: false
      name: Manual - Enable Cortex XDR integration
      type: regular
      version: -1
    taskid: 41184bd3-4ea5-4c0f-8990-f6b1bcaf2edc
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 520,
          "y": 370
        }
      }
  "5":
    id: "5"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "3"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 582019ae-12f5-4b29-823b-a79ef3543d00
      iscommand: false
      name: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors
      type: title
      version: -1
      description: ''
    taskid: 582019ae-12f5-4b29-823b-a79ef3543d00
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 265,
          "y": 50
        }
      }
  "6":
    id: "6"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "7"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: Handled.Techniques
      stringify: {}
      value:
        simple: T1057
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: dbe7e7b0-413d-447c-88ab-ee40819ac2e8
      iscommand: false
      name: Set technique handled
      script: Set
      type: regular
      version: -1
    taskid: dbe7e7b0-413d-447c-88ab-ee40819ac2e8
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 265,
          "y": 720
        }
      }
  "7":
    continueonerror: true
    id: "7"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "2"
    note: false
    quietmode: 0
    scriptarguments:
      columns:
        simple: technique
      context_path:
        simple: Handled.Techniques
      grid_id:
        simple: handledtechniques
      keys: {}
      overwrite: {}
      sort_by: {}
      unpack_nested_elements: {}
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Creates a Grid table from items or key-value pairs.
      id: 31158019-998a-4fb2-8474-c05946f0bc77
      iscommand: false
      name: Set grid field
      script: SetGridField
      type: regular
      version: -1
    taskid: 31158019-998a-4fb2-8474-c05946f0bc77
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 265,
          "y": 900
        }
      }
version: -1
view: |-
  {
    "linkLabelsPosition": {
      "3_1_yes": 0.41
    },
    "paper": {
      "dimensions": {
        "height": 1250,
        "width": 635,
        "x": 265,
        "y": -110
      }
    }
  }
tests:
- No tests (auto formatted)
fromversion: 6.5.0