Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1082 System Information Discovery |
ToolPupy | Pupy can grab a system’s information including the OS version, architecture, etc. |
| T1082 System Information Discovery |
ToolQuasarRAT | QuasarRAT can gather system information from the victim’s machine including the OS type. |
| T1082 System Information Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer has detected if it is on a developer machine by checking if the environmental variable GITHUB_ACTIONS != “true”. TeamPCP Cloud Stealer has also identified readable memory regions on CI/CD runners and enumerated system information using `hostname` and `uname-a`. |
| T1082 System Information Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has gathered system information of victim hosts through the use of common discovery commands to include `hostname`, `uname-a` and `printenv`. Mini Shai-Hulud has also conducted system checks of the victim device to include enumerating the system type and the number of CPUs operating on victim host. |
| T1082 System Information Discovery |
GroupShinyHunters | ShinyHunters has used the MeshCentral command-line utility meshctrl.js to collect hostnames and IDs of compromised systems. |
| T1082 System Information Discovery |
MalwareBADFLICK | BADFLICK has captured victim computer name, memory space, and CPU details. |
| T1083 File and Directory Discovery |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters. |
| T1083 File and Directory Discovery |
CampaignKV Botnet Activity | KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: |
| T1083 File and Directory Discovery |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged commands to locate accessible file shares, backup paths, or SharePoint content. |
| T1083 File and Directory Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used a malicious DLL to search for files with specific keywords. |
| T1083 File and Directory Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to identify sensitive data within the victim environment for extraction. |
| T1083 File and Directory Discovery |
CampaignC0015 | During C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful. |
| T1083 File and Directory Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained information about the configured Exchange virtual directory using `Get-WebServicesVirtualDirectory`. |
| T1083 File and Directory Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace enumerated file system details in compromised environments. |
| T1083 File and Directory Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used `dir c:\\` to search for files. |
| T1083 File and Directory Discovery |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors queried customers' Salesforce environments to identify sensitive information for exfiltration. |
| T1083 File and Directory Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries obtained the contents of users’ directories using `dir /s /b C:\Users` command. |
| T1083 File and Directory Discovery |
CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system. |
| T1083 File and Directory Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors gathered a recursive directory listing to find files and directories of interest. |
| T1083 File and Directory Discovery |
GroupAPT38 | APT38 have enumerated files and directories, or searched in specific locations within a compromised host. |
| T1083 File and Directory Discovery |
GroupAPT3 | APT3 has a tool that looks for files and directories on the local file system. |
| T1083 File and Directory Discovery |
GroupKimsuky | Kimsuky has the ability to enumerate all files and directories on an infected system. Kimsuky has used a custom script with a function called CreateFileList() that can scan all filesystem drives, prioritizing C:\Users, to locate files and file extensions of interest that ultimately generates a file called `FileList.txt` saved within the victims %TEMP% Directory that contains the findings and the respective pathways. |
| T1083 File and Directory Discovery |
Groupadmin@338 | admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about files and directories: |
| T1083 File and Directory Discovery |
GroupVolt Typhoon | Volt Typhoon has enumerated directories containing vulnerability testing and cyber related content and facilities data such as construction drawings. |
| T1083 File and Directory Discovery |
GroupPatchwork | A Patchwork payload has searched all fixed drives on the victim for files matching a specified list of extensions. |
| T1083 File and Directory Discovery |
GroupAPT41 | APT41 has executed |
| T1083 File and Directory Discovery |
GroupDragonfly | Dragonfly has used a batch script to gather folder and file names from victim hosts. |
| T1083 File and Directory Discovery |
GroupmenuPass | menuPass has searched compromised systems for folders of interest including those related to HR, audit and expense, and meeting memos. |
| T1083 File and Directory Discovery |
GroupAPT32 | APT32's backdoor possesses the capability to list files and directories on a machine. |
| T1083 File and Directory Discovery |
GroupHAFNIUM | HAFNIUM has searched file contents on a compromised host. |
| T1083 File and Directory Discovery |
GroupMuddyWater | MuddyWater has used malware that checked if the ProgramData folder had folders or files with the keywords "Kasper," "Panda," or "ESET." |
| T1083 File and Directory Discovery |
GroupGamaredon Group | Gamaredon Group macros can scan for Microsoft Word and Excel files to inject with additional malicious macros. Gamaredon Group has also used its backdoors to automatically list interesting files (such as Office documents) found on a system. Gamaredon Group has also identified directory trees, folders and files on the compromised host. |
| T1083 File and Directory Discovery |
GroupLeafminer | Leafminer used a tool called MailSniper to search for files on the desktop and another utility called Sobolsoft to extract attachments from EML files. |
| T1083 File and Directory Discovery |
GroupTeamTNT | TeamTNT has used a script that checks `/proc/*/environ` for environment variables related to AWS. |
| T1083 File and Directory Discovery |
GroupSandworm Team | Sandworm Team has enumerated files on a compromised host. |
| T1083 File and Directory Discovery |
GroupAPT18 | APT18 can list files information for specific directories. |
| T1083 File and Directory Discovery |
GroupSidewinder | Sidewinder has used malware to collect information on files and directories. |
| T1083 File and Directory Discovery |
GroupMustang Panda | Mustang Panda has searched the entire target system for DOC, DOCX, PPT, PPTX, XLS, XLSX, and PDF files. |
| T1083 File and Directory Discovery |
GroupScattered Spider | Scattered Spider Spider enumerates a target organization for files and directories of interest, including source code, user provisioning, MFA device registration, network diagrams, and shared credentials in documents or spreadsheets. |
| T1083 File and Directory Discovery |
GroupAPT39 | APT39 has used tools with the ability to search for files on a compromised host. |
| T1083 File and Directory Discovery |
GroupUNC3886 | UNC3886 has used `vmtoolsd.exe` to enumerate files on guest machines. |
| T1083 File and Directory Discovery |
GroupContagious Interview | Contagious Interview has conducted key word searches within files and directories on a compromised hosts to identify files for exfiltration. |
| T1083 File and Directory Discovery |
GroupWindigo | Windigo has used a script to check for the presence of files created by OpenSSH backdoors. |
| T1083 File and Directory Discovery |
GroupTropic Trooper | Tropic Trooper has monitored files' modified time. |
| T1083 File and Directory Discovery |
GroupAoqin Dragon | Aoqin Dragon has run scripts to identify file formats including Microsoft Word. |
| T1083 File and Directory Discovery |
GroupKe3chang | Ke3chang uses command-line interaction to search files and directories. |
| T1083 File and Directory Discovery |
GroupConfucius | Confucius has used a file stealer that checks the Document, Downloads, Desktop, and Picture folders for documents and images with specific extensions. |
| T1083 File and Directory Discovery |
GroupWinter Vivern | Winter Vivern delivered malicious JavaScript payloads capable of listing folders and emails in exploited email servers. |
| T1083 File and Directory Discovery |
GroupTurla | Turla surveys a system upon check-in to discover files in specific locations on the hard disk %TEMP% directory, the current user's desktop, the Program Files directory, and Recent. Turla RPC backdoors have also searched for files matching the |
| T1083 File and Directory Discovery |
GroupRedCurl | RedCurl has searched for and collected files on local and network drives. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.