Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareBandook | Bandook has a command to list files on a system. |
| T1083 File and Directory Discovery |
MalwareTINYTYPHON | TINYTYPHON searches through the drive containing the OS, then all drive letters C through to Z, for documents matching certain extensions. |
| T1083 File and Directory Discovery |
MalwareKONNI | A version of KONNI searches for filenames created with a previous version of the malware, suggesting different versions targeted the same victims and the versions may work together. |
| T1083 File and Directory Discovery |
MalwareCORALDECK | CORALDECK searches for specified files. |
| T1083 File and Directory Discovery |
MalwareSPACESHIP | SPACESHIP identifies files and directories for collection by searching for specific file extensions or file modification time. |
| T1083 File and Directory Discovery |
MalwareBLUELIGHT | BLUELIGHT can enumerate files and collect associated metadata. |
| T1083 File and Directory Discovery |
MalwareKGH_SPY | KGH_SPY can enumerate files and directories on a compromised host. |
| T1083 File and Directory Discovery |
Malwaredown_new | down_new has the ability to list the directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareIxeshe | Ixeshe can list file and directory information. |
| T1083 File and Directory Discovery |
MalwareMicropsia | Micropsia can perform a recursive directory listing for all volume drives available on the victim's machine and can also fetch specific files by their paths. |
| T1083 File and Directory Discovery |
MalwareRARSTONE | RARSTONE obtains installer properties from Uninstall Registry Key entries to obtain information about installed applications and how to uninstall certain applications. |
| T1083 File and Directory Discovery |
MalwareBlack Basta | Black Basta can enumerate specific files for encryption. |
| T1083 File and Directory Discovery |
Malware4H RAT | 4H RAT has the capability to obtain file and directory listings. |
| T1083 File and Directory Discovery |
MalwareAttor | Attor has a plugin that enumerates files with specific extensions on all hard disk drives and stores file information in encrypted log files. |
| T1083 File and Directory Discovery |
MalwareMegaCortex | MegaCortex can parse the available drives and directories to determine which files to encrypt. |
| T1083 File and Directory Discovery |
MalwareStreamEx | StreamEx has the ability to enumerate drive types. |
| T1083 File and Directory Discovery |
MalwareBoxCaon | BoxCaon has searched for files on the system, such as documents located in the desktop folder. |
| T1083 File and Directory Discovery |
MalwareNightClub | NightClub can use a file monitor to identify .lnk, .doc, .docx, .xls, .xslx, and .pdf files. |
| T1083 File and Directory Discovery |
MalwareAkira _v2 | Akira _v2 can target specific files and folders for encryption. |
| T1083 File and Directory Discovery |
MalwareSDBbot | SDBbot has the ability to get directory listings or drive information on a compromised host. |
| T1083 File and Directory Discovery |
MalwareRTM | RTM can check for specific files and directories associated with virtualization and malware analysis. |
| T1083 File and Directory Discovery |
MalwareDerusbi | Derusbi is capable of obtaining directory, file, and drive listings. |
| T1083 File and Directory Discovery |
MalwareBazar | Bazar can enumerate the victim's desktop. |
| T1083 File and Directory Discovery |
MalwareBadPatch | BadPatch searches for files with specific file extensions. |
| T1083 File and Directory Discovery |
MalwareMESSAGETAP | MESSAGETAP checks for the existence of two configuration files (keyword_parm.txt and parm.txt) and attempts to read the files every 30 seconds. |
| T1083 File and Directory Discovery |
MalwareSUGARDUMP | SUGARDUMP can search for and collect data from specific Chrome, Opera, Microsoft Edge, and Firefox files, including any folders that have the string `Profile` in its name. |
| T1083 File and Directory Discovery |
MalwareSOUNDBITE | SOUNDBITE is capable of enumerating and manipulating files and directories. |
| T1083 File and Directory Discovery |
MalwareMoonWind | MoonWind has a command to return a directory listing for a specified directory. |
| T1083 File and Directory Discovery |
MalwareRyuk | Ryuk has enumerated files and folders on all mounted drives. |
| T1083 File and Directory Discovery |
MalwareCryptoistic | Cryptoistic can scan a directory to identify files for deletion. |
| T1083 File and Directory Discovery |
MalwareHermeticWiper | HermeticWiper can enumerate common folders such as My Documents, Desktop, and AppData. |
| T1083 File and Directory Discovery |
Malwareccf32 | ccf32 can parse collected files to identify specific file extensions. |
| T1083 File and Directory Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can exclude files associated with core system functions from encryption. |
| T1083 File and Directory Discovery |
MalwareZebrocy | Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the |
| T1083 File and Directory Discovery |
MalwareFinFisher | FinFisher enumerates directories and scans for certain files. |
| T1083 File and Directory Discovery |
MalwareLunarMail | LunarMail can search its staging directory for output files it has produced. |
| T1083 File and Directory Discovery |
MalwareCrossRAT | CrossRAT can list all files on a system. |
| T1083 File and Directory Discovery |
MalwareOwaAuth | OwaAuth has a command to list its directory and logical drives. |
| T1083 File and Directory Discovery |
MalwareCobalt Strike | Cobalt Strike can explore files on a compromised system. |
| T1083 File and Directory Discovery |
MalwareSUNBURST | SUNBURST had commands to enumerate files and directories. |
| T1083 File and Directory Discovery |
MalwareHotCroissant | HotCroissant has the ability to retrieve a list of files in a given directory as well as drives and drive types. |
| T1083 File and Directory Discovery |
MalwareREvil | REvil has the ability to identify specific files and directories that are not to be encrypted. |
| T1083 File and Directory Discovery |
MalwareSamurai | Samurai can use a specific module for file enumeration. |
| T1083 File and Directory Discovery |
MalwarePinchDuke | PinchDuke searches for files created within a certain timeframe and whose file extension matches a predefined list. |
| T1083 File and Directory Discovery |
MalwareUSBStealer | USBStealer searches victim drives for files matching certain extensions (“.skr”,“.pkr” or “.key”) or names. |
| T1083 File and Directory Discovery |
MalwareTaidoor | Taidoor can search for specific files. |
| T1083 File and Directory Discovery |
MalwareKivars | Kivars has the ability to list drives on the infected host. |
| T1083 File and Directory Discovery |
MalwareCaddyWiper | CaddyWiper can enumerate all files and directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareCyclops Blink | Cyclops Blink can use the Linux API `statvfs` to enumerate the current working directory. |
| T1083 File and Directory Discovery |
MalwareSeasalt | Seasalt has the capability to identify the drive type on a victim. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.