ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1135×

57 examples

TechniqueUsed byProcedure example
T1135
Network Share Discovery
MalwareTrickBot

TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API.

T1135
Network Share Discovery
MalwareQuietSieve

QuietSieve can identify and search networked drives for specific file name extensions.

T1135
Network Share Discovery
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about shares on remote hosts.

T1135
Network Share Discovery
MalwareStuxnet

Stuxnet enumerates the directories of a network resource.

T1135
Network Share Discovery
MalwareAvosLocker

AvosLocker has enumerated shared drives on a compromised network.

T1135
Network Share Discovery
MalwareKOPILUWAK

KOPILUWAK can use netstat and Net to discover network shares.

T1135
Network Share Discovery
MalwareSardonic

Sardonic has the ability to execute the `net view` command.

T1135
Network Share Discovery
MalwareRansomHub

RansomHub has the ability to target specific network shares for encryption.

T1135
Network Share Discovery
MalwareMedusa Ransomware

Medusa Ransomware has identified networked drives.

T1135
Network Share Discovery
MalwareBad Rabbit

Bad Rabbit enumerates open SMB shares on internal victim networks.

T1135
Network Share Discovery
MalwareEmotet

Emotet has enumerated non-hidden network shares using `WNetEnumResourceW`.

T1135
Network Share Discovery
MalwareOlympic Destroyer

Olympic Destroyer will attempt to enumerate mapped network shares to later attempt to wipe all files on those shares.

T1135
Network Share Discovery
MalwareDUSTTRAP

DUSTTRAP can identify and enumerate victim system network shares.

T1135
Network Share Discovery
MalwareBADHATCH

BADHATCH can check a user's access to the C$ share on a compromised machine.

T1135
Network Share Discovery
MalwareBlackByte 2.0 Ransomware

BlackByte 2.0 Ransomware can identify network shares connected to the victim machine.

T1135
Network Share Discovery
MalwareWastedLocker

WastedLocker can identify network adjacent and accessible drives.

T1135
Network Share Discovery
MalwareInvisiMole

InvisiMole can gather network share information.

T1135
Network Share Discovery
MalwareWhisperGate

WhisperGate can enumerate connected remote logical drives.

T1135
Network Share Discovery
MalwareConti

Conti can enumerate remote open SMB network shares using NetShareEnum().

T1135
Network Share Discovery
MalwareDiavol

Diavol has a `ENMDSKS` command to enumerates available network shares.

T1135
Network Share Discovery
MalwareBlackCat

BlackCat has the ability to discover network shares on compromised networks.

T1135
Network Share Discovery
MalwareIcedID

IcedID has used the `net view /all` command to show available shares.

T1135
Network Share Discovery
MalwareShimRat

ShimRat can enumerate connected drives for infected host machines.

T1135
Network Share Discovery
MalwareAvaddon

Avaddon has enumerated shared folders and mapped volumes.

T1135
Network Share Discovery
MalwareFlagpro

Flagpro has been used to execute `net view` to discover mapped network shares.

T1135
Network Share Discovery
MalwareHELLOKITTY

HELLOKITTY has the ability to enumerate network resources.

T1135
Network Share Discovery
MalwareBabuk

Babuk has the ability to enumerate network shares.

T1135
Network Share Discovery
MalwarePlugX

PlugX has a module to enumerate network shares.

T1135
Network Share Discovery
MalwareCuba

Cuba can discover shared resources using the NetShareEnum API call.

T1135
Network Share Discovery
MalwareDEATHRANSOM

DEATHRANSOM has the ability to use loop operations to enumerate network resources.

T1135
Network Share Discovery
MalwareClambling

Clambling has the ability to enumerate network shares.

T1135
Network Share Discovery
MalwareAkira

Akira can identify remote file shares for encryption.

T1135
Network Share Discovery
MalwareLockBit 3.0

LockBit 3.0 can identify network shares on compromised systems.

T1135
Network Share Discovery
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares.

T1135
Network Share Discovery
MalwareRoyal

Royal can enumerate the shared resources of a given IP addresses using the API call `NetShareEnum`.

T1135
Network Share Discovery
MalwareEmbargo

Embargo has searched for folders, subfolders and other networked or mounted drives for follow-on encryption actions.

T1135
Network Share Discovery
MalwareBlackByte Ransomware

BlackByte Ransomware can identify network shares connected to the victim machine.

T1135
Network Share Discovery
MalwareBazar

Bazar can enumerate shared drives on the domain.

T1135
Network Share Discovery
MalwareLockBit 2.0

LockBit 2.0 can discover remote shares.

T1135
Network Share Discovery
MalwareZebrocy

Zebrocy identifies network drives when they are added to victim systems.

T1135
Network Share Discovery
MalwareCobalt Strike

Cobalt Strike can query shared drives on the local system.

T1135
Network Share Discovery
MalwareRamsay

Ramsay can scan for network drives which may contain documents for collection.

T1135
Network Share Discovery
MalwareKwampirs

Kwampirs collects a list of network shares with the command net share.

T1135
Network Share Discovery
MalwareClop

Clop can enumerate network shares.

T1135
Network Share Discovery
MalwareLunarWeb

LunarWeb can identify shared resources in compromised environments.

T1135
Network Share Discovery
MalwareQilin

Qilin has the ability to list network drives.

T1135
Network Share Discovery
MalwareQakBot

QakBot can use net share to identify network shares for use in lateral movement.

T1135
Network Share Discovery
MalwareINC Ransomware

INC Ransomware has the ability to check for shared network drives to encrypt.

T1135
Network Share Discovery
MalwareFIVEHANDS

FIVEHANDS can enumerate network shares and mounted drives on a network.

T1135
Network Share Discovery
MalwareOSInfo

OSInfo discovers shares on the network

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.