Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
GroupLotus Blossom | Lotus Blossom has used commands such as `dir` to examine the local filesystem of victim machines. |
| T1083 File and Directory Discovery |
GroupDark Caracal | Dark Caracal collected file listings of all default Windows directories. |
| T1083 File and Directory Discovery |
GroupChimera | Chimera has utilized multiple commands to identify data of interest in file and directory listings. |
| T1083 File and Directory Discovery |
GroupMirrorFace | MirrorFace has run commands to check the content of folders on compromised hosts and has specifically targeted files with .doc, .ppt, .xls, .jtd, .eml, .xps, and .pdf extensions. |
| T1083 File and Directory Discovery |
GroupMedusa Group | Medusa Group has searched for files within the victim environment for encryption and exfiltration. Medusa Group has also identified files associated with remote management services. |
| T1083 File and Directory Discovery |
GroupBRONZE BUTLER | BRONZE BUTLER has collected a list of files from the victim and uploaded it to its C2 server, and then created a new list of specific files to steal. |
| T1083 File and Directory Discovery |
GroupDarkhotel | Darkhotel has used malware that searched for files with specific patterns. |
| T1083 File and Directory Discovery |
GroupToddyCat | ToddyCat has run scripts to enumerate recently modified documents having either a .pdf, .doc, .docx, .xls or .xlsx extension. |
| T1083 File and Directory Discovery |
GroupLuminousMoth | LuminousMoth has used malware that scans for files in the Documents, Desktop, and Download folders and in other drives. |
| T1083 File and Directory Discovery |
GroupAPT28 | APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection. The group also searched a compromised DCCC computer for specific terms. |
| T1083 File and Directory Discovery |
GroupAPT5 | APT5 has used the BLOODMINE utility to discover files with .css, .jpg, .png, .gif, .ico, .js, and .jsp extensions in Pulse Secure Connect logs. |
| T1083 File and Directory Discovery |
GroupFox Kitten | Fox Kitten has used WizTree to obtain network files and directory listings. |
| T1083 File and Directory Discovery |
GroupWinnti Group | Winnti Group has used a program named ff.exe to search for specific documents on compromised hosts. |
| T1083 File and Directory Discovery |
GroupLazarus Group | Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives. |
| T1083 File and Directory Discovery |
GroupSowbug | Sowbug identified and extracted all Word documents on a server by using a command containing * .doc and *.docx. The actors also searched for documents based on a specific date range and attempted to identify all installed software on a victim. |
| T1083 File and Directory Discovery |
GroupVelvet Ant | Velvet Ant has enumerated local files and folders on victim devices. |
| T1083 File and Directory Discovery |
GroupInception | Inception used a file listing plugin to collect information about file and directories both on local and remote drives. |
| T1083 File and Directory Discovery |
GroupPlay | Play has used the Grixba information stealer to list security files and processes. |
| T1083 File and Directory Discovery |
GroupMagic Hound | Magic Hound malware can list a victim's logical drives and the type, as well the total/free space of the fixed devices. Other malware can list a directory's contents. |
| T1083 File and Directory Discovery |
GroupFIN13 | FIN13 has used the Windows `dir` command to enumerate files and directories in a victim's network. |
| T1083 File and Directory Discovery |
MalwareTrickBot | TrickBot searches the system for all of the following file extensions: .avi, .mov, .mkv, .mpeg, .mpeg4, .mp4, .mp3, .wav, .ogg, .jpeg, .jpg, .png, .bmp, .gif, .tiff, .ico, .xlsx, and .zip. It can also obtain browsing history, cookies, and plug-in information. |
| T1083 File and Directory Discovery |
MalwarePowerDuke | PowerDuke has commands to get the current directory name as well as the size of a file. It also has commands to obtain information about logical drives, drive type, and free space. |
| T1083 File and Directory Discovery |
MalwareBLINDINGCAN | BLINDINGCAN can search, read, write, move, and execute files. |
| T1083 File and Directory Discovery |
MalwareNinja | Ninja has the ability to enumerate directory content. |
| T1083 File and Directory Discovery |
MalwareQuietSieve | QuietSieve can search files on the target host by extension, including doc, docx, xls, rtf, odt, txt, jpg, pdf, rar, zip, and 7z. |
| T1083 File and Directory Discovery |
MalwareSynAck | SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
| T1083 File and Directory Discovery |
MalwareBRICKSTORM | BRICKSTORM has identified specific files and directories within targeted hosts and systems for modification, execution, collection and exfiltration. |
| T1083 File and Directory Discovery |
MalwareAcidRain | AcidRain identifies specific files and directories in the Linux operating system associated with storage devices. |
| T1083 File and Directory Discovery |
MalwareAmadey | Amadey has searched for folders associated with antivirus software. |
| T1083 File and Directory Discovery |
MalwareProxysvc | Proxysvc lists files in directories. |
| T1083 File and Directory Discovery |
MalwareOrz | Orz can gather victim drive information. |
| T1083 File and Directory Discovery |
Malwareyty | yty gathers information on victim’s drives and has a plugin for document listing. |
| T1083 File and Directory Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about available drives, default browser, desktop file list, My Documents, Internet history, program files, and root of available drives. It also searches for ICS-related software files. |
| T1083 File and Directory Discovery |
MalwareStuxnet | Stuxnet uses a driver to scan for specific filesystem driver objects. |
| T1083 File and Directory Discovery |
MalwareAvosLocker | AvosLocker has searched for files and directories on a compromised network. |
| T1083 File and Directory Discovery |
MalwarePOWRUNER | POWRUNER may enumerate user directories on a victim. |
| T1083 File and Directory Discovery |
MalwareCOATHANGER | COATHANGER will survey the contents of system files during installation. |
| T1083 File and Directory Discovery |
MalwareSmoke Loader | Smoke Loader recursively searches through directories for files. |
| T1083 File and Directory Discovery |
MalwareWindTail | WindTail has the ability to enumerate the users home directory and the path to its own application bundle. |
| T1083 File and Directory Discovery |
MalwareMisdat | Misdat is capable of running commands to obtain a list of files and directories, as well as enumerating logical drives. |
| T1083 File and Directory Discovery |
MalwareKEYMARBLE | KEYMARBLE has a command to search for files on the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareThreatNeedle | ThreatNeedle can obtain file and directory information. |
| T1083 File and Directory Discovery |
MalwareRansomHub | RansomHub has the ability to only encrypt specific files. |
| T1083 File and Directory Discovery |
MalwareZLib | ZLib has the ability to enumerate files and drives. |
| T1083 File and Directory Discovery |
MalwareRedLeaves | RedLeaves can enumerate and search for files and directories. |
| T1083 File and Directory Discovery |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can monitor for system upgrade events by checking for the presence of `/tmp/data/root/dev`. |
| T1083 File and Directory Discovery |
MalwareZeus Panda | Zeus Panda searches for specific directories on the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareGeminiDuke | GeminiDuke collects information from the victim, including installed drivers, programs previously executed by users, programs and services configured to automatically run at startup, files and folders present in any user's home folder, files and folders present in any user's My Documents, programs installed to the Program Files folder, and recently accessed files, folders, and programs. |
| T1083 File and Directory Discovery |
MalwareHavoc | The Havoc interface can display a file explorer view of the compromised host. |
| T1083 File and Directory Discovery |
MalwareGravityRAT | GravityRAT collects the volumes mapped on the system, and also steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.