ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1083×

52 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
GroupAPT38

APT38 have enumerated files and directories, or searched in specific locations within a compromised host.

T1083
File and Directory Discovery
GroupAPT3

APT3 has a tool that looks for files and directories on the local file system.

T1083
File and Directory Discovery
GroupKimsuky

Kimsuky has the ability to enumerate all files and directories on an infected system. Kimsuky has used a custom script with a function called CreateFileList() that can scan all filesystem drives, prioritizing C:\Users, to locate files and file extensions of interest that ultimately generates a file called `FileList.txt` saved within the victims %TEMP% Directory that contains the findings and the respective pathways.

T1083
File and Directory Discovery
Groupadmin@338

admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about files and directories: dir c:\ >> %temp%\download dir "c:\Documents and Settings" >> %temp%\download dir "c:\Program Files\" >> %temp%\download dir d:\ >> %temp%\download

T1083
File and Directory Discovery
GroupVolt Typhoon

Volt Typhoon has enumerated directories containing vulnerability testing and cyber related content and facilities data such as construction drawings.

T1083
File and Directory Discovery
GroupPatchwork

A Patchwork payload has searched all fixed drives on the victim for files matching a specified list of extensions.

T1083
File and Directory Discovery
GroupAPT41

APT41 has executed file /bin/pwd on exploited victims, perhaps to return architecture related information.

T1083
File and Directory Discovery
GroupDragonfly

Dragonfly has used a batch script to gather folder and file names from victim hosts.

T1083
File and Directory Discovery
GroupmenuPass

menuPass has searched compromised systems for folders of interest including those related to HR, audit and expense, and meeting memos.

T1083
File and Directory Discovery
GroupAPT32

APT32's backdoor possesses the capability to list files and directories on a machine.

T1083
File and Directory Discovery
GroupHAFNIUM

HAFNIUM has searched file contents on a compromised host.

T1083
File and Directory Discovery
GroupMuddyWater

MuddyWater has used malware that checked if the ProgramData folder had folders or files with the keywords "Kasper," "Panda," or "ESET."

T1083
File and Directory Discovery
GroupGamaredon Group

Gamaredon Group macros can scan for Microsoft Word and Excel files to inject with additional malicious macros. Gamaredon Group has also used its backdoors to automatically list interesting files (such as Office documents) found on a system. Gamaredon Group has also identified directory trees, folders and files on the compromised host.

T1083
File and Directory Discovery
GroupLeafminer

Leafminer used a tool called MailSniper to search for files on the desktop and another utility called Sobolsoft to extract attachments from EML files.

T1083
File and Directory Discovery
GroupTeamTNT

TeamTNT has used a script that checks `/proc/*/environ` for environment variables related to AWS.

T1083
File and Directory Discovery
GroupSandworm Team

Sandworm Team has enumerated files on a compromised host.

T1083
File and Directory Discovery
GroupAPT18

APT18 can list files information for specific directories.

T1083
File and Directory Discovery
GroupSidewinder

Sidewinder has used malware to collect information on files and directories.

T1083
File and Directory Discovery
GroupMustang Panda

Mustang Panda has searched the entire target system for DOC, DOCX, PPT, PPTX, XLS, XLSX, and PDF files.

T1083
File and Directory Discovery
GroupScattered Spider

Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets.

T1083
File and Directory Discovery
GroupAPT39

APT39 has used tools with the ability to search for files on a compromised host.

T1083
File and Directory Discovery
GroupUNC3886

UNC3886 has used `vmtoolsd.exe` to enumerate files on guest machines.

T1083
File and Directory Discovery
GroupContagious Interview

Contagious Interview has conducted key word searches within files and directories on a compromised hosts to identify files for exfiltration.

T1083
File and Directory Discovery
GroupWindigo

Windigo has used a script to check for the presence of files created by OpenSSH backdoors.

T1083
File and Directory Discovery
GroupTropic Trooper

Tropic Trooper has monitored files' modified time.

T1083
File and Directory Discovery
GroupAoqin Dragon

Aoqin Dragon has run scripts to identify file formats including Microsoft Word.

T1083
File and Directory Discovery
GroupKe3chang

Ke3chang uses command-line interaction to search files and directories.

T1083
File and Directory Discovery
GroupConfucius

Confucius has used a file stealer that checks the Document, Downloads, Desktop, and Picture folders for documents and images with specific extensions.

T1083
File and Directory Discovery
GroupWinter Vivern

Winter Vivern delivered malicious JavaScript payloads capable of listing folders and emails in exploited email servers.

T1083
File and Directory Discovery
GroupTurla

Turla surveys a system upon check-in to discover files in specific locations on the hard disk %TEMP% directory, the current user's desktop, the Program Files directory, and Recent. Turla RPC backdoors have also searched for files matching the lPH*.dll pattern.

T1083
File and Directory Discovery
GroupRedCurl

RedCurl has searched for and collected files on local and network drives.

T1083
File and Directory Discovery
GroupLotus Blossom

Lotus Blossom has used commands such as `dir` to examine the local filesystem of victim machines.

T1083
File and Directory Discovery
GroupDark Caracal

Dark Caracal collected file listings of all default Windows directories.

T1083
File and Directory Discovery
GroupChimera

Chimera has utilized multiple commands to identify data of interest in file and directory listings.

T1083
File and Directory Discovery
GroupMirrorFace

MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions.

T1083
File and Directory Discovery
GroupMedusa Group

Medusa Group has searched for files within the victim environment for encryption and exfiltration. Medusa Group has also identified files associated with remote management services.

T1083
File and Directory Discovery
GroupBRONZE BUTLER

BRONZE BUTLER has collected a list of files from the victim and uploaded it to its C2 server, and then created a new list of specific files to steal.

T1083
File and Directory Discovery
GroupDarkhotel

Darkhotel has used malware that searched for files with specific patterns.

T1083
File and Directory Discovery
GroupToddyCat

ToddyCat has run scripts to enumerate recently modified documents having either a .pdf, .doc, .docx, .xls or .xlsx extension.

T1083
File and Directory Discovery
GroupLuminousMoth

LuminousMoth has used malware that scans for files in the Documents, Desktop, and Download folders and in other drives.

T1083
File and Directory Discovery
GroupAPT28

APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection. The group also searched a compromised DCCC computer for specific terms.

T1083
File and Directory Discovery
GroupAPT5

APT5 has used the BLOODMINE utility to discover files with .css, .jpg, .png, .gif, .ico, .js, and .jsp extensions in Pulse Secure Connect logs.

T1083
File and Directory Discovery
GroupFox Kitten

Fox Kitten has used WizTree to obtain network files and directory listings.

T1083
File and Directory Discovery
GroupWinnti Group

Winnti Group has used a program named ff.exe to search for specific documents on compromised hosts.

T1083
File and Directory Discovery
GroupLazarus Group

Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives.

T1083
File and Directory Discovery
GroupSowbug

Sowbug identified and extracted all Word documents on a server by using a command containing * .doc and *.docx. The actors also searched for documents based on a specific date range and attempted to identify all installed software on a victim.

T1083
File and Directory Discovery
GroupVelvet Ant

Velvet Ant has enumerated local files and folders on victim devices.

T1083
File and Directory Discovery
GroupInception

Inception used a file listing plugin to collect information about file and directories both on local and remote drives.

T1083
File and Directory Discovery
GroupPlay

Play has used the Grixba information stealer to list security files and processes.

T1083
File and Directory Discovery
GroupMagic Hound

Magic Hound malware can list a victim's logical drives and the type, as well the total/free space of the fixed devices. Other malware can list a directory's contents.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.