Real-world descriptions of how a group, tool or campaign used a technique.
57 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1135 Network Share Discovery |
MalwareTrickBot | TrickBot module shareDll/mshareDll discovers network shares via the WNetOpenEnumA API. |
| T1135 Network Share Discovery |
MalwareQuietSieve | QuietSieve can identify and search networked drives for specific file name extensions. |
| T1135 Network Share Discovery |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about shares on remote hosts. |
| T1135 Network Share Discovery |
MalwareStuxnet | Stuxnet enumerates the directories of a network resource. |
| T1135 Network Share Discovery |
MalwareAvosLocker | AvosLocker has enumerated shared drives on a compromised network. |
| T1135 Network Share Discovery |
MalwareKOPILUWAK | KOPILUWAK can use netstat and Net to discover network shares. |
| T1135 Network Share Discovery |
MalwareSardonic | Sardonic has the ability to execute the `net view` command. |
| T1135 Network Share Discovery |
MalwareRansomHub | RansomHub has the ability to target specific network shares for encryption. |
| T1135 Network Share Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has identified networked drives. |
| T1135 Network Share Discovery |
MalwareBad Rabbit | Bad Rabbit enumerates open SMB shares on internal victim networks. |
| T1135 Network Share Discovery |
MalwareEmotet | Emotet has enumerated non-hidden network shares using `WNetEnumResourceW`. |
| T1135 Network Share Discovery |
MalwareOlympic Destroyer | Olympic Destroyer will attempt to enumerate mapped network shares to later attempt to wipe all files on those shares. |
| T1135 Network Share Discovery |
MalwareDUSTTRAP | DUSTTRAP can identify and enumerate victim system network shares. |
| T1135 Network Share Discovery |
MalwareBADHATCH | BADHATCH can check a user's access to the C$ share on a compromised machine. |
| T1135 Network Share Discovery |
MalwareBlackByte 2.0 Ransomware | BlackByte 2.0 Ransomware can identify network shares connected to the victim machine. |
| T1135 Network Share Discovery |
MalwareWastedLocker | WastedLocker can identify network adjacent and accessible drives. |
| T1135 Network Share Discovery |
MalwareInvisiMole | InvisiMole can gather network share information. |
| T1135 Network Share Discovery |
MalwareWhisperGate | WhisperGate can enumerate connected remote logical drives. |
| T1135 Network Share Discovery |
MalwareConti | Conti can enumerate remote open SMB network shares using |
| T1135 Network Share Discovery |
MalwareDiavol | Diavol has a `ENMDSKS` command to enumerates available network shares. |
| T1135 Network Share Discovery |
MalwareBlackCat | BlackCat has the ability to discover network shares on compromised networks. |
| T1135 Network Share Discovery |
MalwareIcedID | IcedID has used the `net view /all` command to show available shares. |
| T1135 Network Share Discovery |
MalwareShimRat | ShimRat can enumerate connected drives for infected host machines. |
| T1135 Network Share Discovery |
MalwareAvaddon | Avaddon has enumerated shared folders and mapped volumes. |
| T1135 Network Share Discovery |
MalwareFlagpro | Flagpro has been used to execute `net view` to discover mapped network shares. |
| T1135 Network Share Discovery |
MalwareHELLOKITTY | HELLOKITTY has the ability to enumerate network resources. |
| T1135 Network Share Discovery |
MalwareBabuk | Babuk has the ability to enumerate network shares. |
| T1135 Network Share Discovery |
MalwarePlugX | PlugX has a module to enumerate network shares. |
| T1135 Network Share Discovery |
MalwareCuba | Cuba can discover shared resources using the |
| T1135 Network Share Discovery |
MalwareDEATHRANSOM | DEATHRANSOM has the ability to use loop operations to enumerate network resources. |
| T1135 Network Share Discovery |
MalwareClambling | Clambling has the ability to enumerate network shares. |
| T1135 Network Share Discovery |
MalwareAkira | Akira can identify remote file shares for encryption. |
| T1135 Network Share Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can identify network shares on compromised systems. |
| T1135 Network Share Discovery |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c net view /all` to discover network shares. |
| T1135 Network Share Discovery |
MalwareRoyal | Royal can enumerate the shared resources of a given IP addresses using the API call `NetShareEnum`. |
| T1135 Network Share Discovery |
MalwareEmbargo | Embargo has searched for folders, subfolders and other networked or mounted drives for follow-on encryption actions. |
| T1135 Network Share Discovery |
MalwareBlackByte Ransomware | BlackByte Ransomware can identify network shares connected to the victim machine. |
| T1135 Network Share Discovery |
MalwareBazar | Bazar can enumerate shared drives on the domain. |
| T1135 Network Share Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can discover remote shares. |
| T1135 Network Share Discovery |
MalwareZebrocy | Zebrocy identifies network drives when they are added to victim systems. |
| T1135 Network Share Discovery |
MalwareCobalt Strike | Cobalt Strike can query shared drives on the local system. |
| T1135 Network Share Discovery |
MalwareRamsay | Ramsay can scan for network drives which may contain documents for collection. |
| T1135 Network Share Discovery |
MalwareKwampirs | Kwampirs collects a list of network shares with the command |
| T1135 Network Share Discovery |
MalwareClop | Clop can enumerate network shares. |
| T1135 Network Share Discovery |
MalwareLunarWeb | LunarWeb can identify shared resources in compromised environments. |
| T1135 Network Share Discovery |
MalwareQilin | Qilin has the ability to list network drives. |
| T1135 Network Share Discovery |
MalwareQakBot | QakBot can use |
| T1135 Network Share Discovery |
MalwareINC Ransomware | INC Ransomware has the ability to check for shared network drives to encrypt. |
| T1135 Network Share Discovery |
MalwareFIVEHANDS | FIVEHANDS can enumerate network shares and mounted drives on a network. |
| T1135 Network Share Discovery |
MalwareOSInfo | OSInfo discovers shares on the network |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.