Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwarePrestige | Prestige can traverse the file system to discover files to encrypt by identifying specific extensions defined in a hardcoded list. |
| T1083 File and Directory Discovery |
MalwareInvisibleFerret | InvisibleFerret has identified specific directories and files for exfiltration using the `ssh_upload` command which contains subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr`, `sfind`. InvisibleFerret also has the capability to scan and upload files of interest from multiple OS systems through the use of scripts that check file names, file extensions, and avoids certain path names. InvisibleFerret has utilized the `findstr` on Windows or the macOS `find` commands to search for files of interest. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1083 File and Directory Discovery |
MalwareBankshot | Bankshot searches for files on the victim's machine. |
| T1083 File and Directory Discovery |
MalwareSharpDisco | SharpDisco can identify recently opened files by using an LNK format parser to extract the original file path from LNK files found in either `%USERPROFILE%\Recent` (Windows XP) or `%APPDATA%\Microsoft\Windows\Recent` (newer Windows versions) . |
| T1083 File and Directory Discovery |
MalwareStrongPity | StrongPity can parse the hard drive on a compromised host to identify specific file extensions. |
| T1083 File and Directory Discovery |
MalwareWinMM | WinMM sets a WH_CBT Windows hook to search for and capture files on the victim. |
| T1083 File and Directory Discovery |
MalwareNebulae | Nebulae can list files and directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareAuditCred | AuditCred can search through folders and files on the system. |
| T1083 File and Directory Discovery |
MalwareKasidet | Kasidet has the ability to search for a given filename on a victim. |
| T1083 File and Directory Discovery |
MalwareOceanSalt | OceanSalt can extract drive information from the endpoint and search files on the system. |
| T1083 File and Directory Discovery |
MalwarePlaycrypt | Playcrypt can avoid encrypting files with a .PLAY, .exe, .msi, .dll, .lnk, or .sys file extension. |
| T1083 File and Directory Discovery |
MalwareBrave Prince | Brave Prince gathers file and directory information from the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has searched for files within the victim environment for encryption and exfiltration. Medusa Ransomware has also identified files associated with remote management services. |
| T1083 File and Directory Discovery |
MalwareRainyDay | RainyDay can use a file exfiltration tool to collect recently changed files with specific extensions. |
| T1083 File and Directory Discovery |
MalwareAppleSeed | AppleSeed has the ability to search for .txt, .ppt, .hwp, .pdf, and .doc files in specified directories. |
| T1083 File and Directory Discovery |
MalwareNETWIRE | NETWIRE has the ability to search for files on the compromised host. |
| T1083 File and Directory Discovery |
MalwareCosmicDuke | CosmicDuke searches attached and mounted drives for file extensions and keywords that match a predefined list. |
| T1083 File and Directory Discovery |
MalwareGomir | Gomir collects information about directory and file structures, including total number of subdirectories, total number of files, and total size of files on infected systems. |
| T1083 File and Directory Discovery |
MalwareAria-body | Aria-body has the ability to gather metadata from a file and to search for file and directory names. |
| T1083 File and Directory Discovery |
MalwareBOLDMOVE | BOLDMOVE can list information of all files in the system recursively from the root directory or from a specified directory. |
| T1083 File and Directory Discovery |
MalwareCrimson | Crimson contains commands to list files and directories, as well as search for files matching certain extensions from a defined list. |
| T1083 File and Directory Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate files and directories. |
| T1083 File and Directory Discovery |
MalwareDynoWiper | DynoWiper has used the Microsoft Windows native `FindFirstFile()` and `FindNextFile()` to recursively enumerate directories and files on the system. |
| T1083 File and Directory Discovery |
MalwareTurian | Turian can search for specific files and list directories. |
| T1083 File and Directory Discovery |
MalwareMachete | Machete produces file listings in order to search for files to be exfiltrated. |
| T1083 File and Directory Discovery |
MalwareAction RAT | Action RAT has the ability to collect drive and file information on an infected machine. |
| T1083 File and Directory Discovery |
MalwareAvenger | Avenger has the ability to browse files in directories such as Program Files and the Desktop. |
| T1083 File and Directory Discovery |
MalwarePrikormka | A module in Prikormka collects information about the paths, size, and creation time of files with specific file extensions, but not the actual content of the file. |
| T1083 File and Directory Discovery |
MalwarePingPull | PingPull can enumerate storage volumes and folder contents of a compromised host. |
| T1083 File and Directory Discovery |
MalwareDacls | Dacls can scan directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareDropBook | DropBook can collect the names of all files and folders in the Program Files directories. |
| T1083 File and Directory Discovery |
MalwareWoody RAT | Woody RAT can list all files and their associated attributes, including filename, type, owner, creation time, last access time, last write time, size, and permissions. |
| T1083 File and Directory Discovery |
MalwareMafalda | Mafalda can search for files and directories. |
| T1083 File and Directory Discovery |
MalwareELMER | ELMER is capable of performing directory listings. |
| T1083 File and Directory Discovery |
MalwareSombRAT | SombRAT can execute |
| T1083 File and Directory Discovery |
MalwareODAgent | ODAgent can identify the current working directory. |
| T1083 File and Directory Discovery |
MalwareFLASHFLOOD | FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on the local system and removable media. |
| T1083 File and Directory Discovery |
MalwareFYAnti | FYAnti can search the |
| T1083 File and Directory Discovery |
MalwareLoFiSe | LoFiSe can monitor the file system to identify files less than 6.4 MB in size with file extensions including .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .rtf, .tif, .odt, .ods, .odp, .eml, and .msg. |
| T1083 File and Directory Discovery |
MalwareHOPLIGHT | HOPLIGHT has been observed enumerating system drives and partitions. |
| T1083 File and Directory Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can search for files associated with specific applications. |
| T1083 File and Directory Discovery |
MalwareMobileOrder | MobileOrder has a command to upload to its C2 server information about files on the victim mobile device, including SD card size, installed app list, SMS content, contacts, and calling history. |
| T1083 File and Directory Discovery |
MalwareWastedLocker | WastedLocker can enumerate files and directories just prior to encryption. |
| T1083 File and Directory Discovery |
MalwareInvisiMole | InvisiMole can list information about files in a directory and recently opened or used documents. InvisiMole can also search for specific files by supplied file mask. |
| T1083 File and Directory Discovery |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to list files and file characteristics including extension, size, ownership, and permissions. |
| T1083 File and Directory Discovery |
MalwareVolgmer | Volgmer can list directories on a victim. |
| T1083 File and Directory Discovery |
MalwareWINERACK | WINERACK can enumerate files and directories. |
| T1083 File and Directory Discovery |
MalwareWhisperGate | WhisperGate can locate files based on hardcoded file extensions. |
| T1083 File and Directory Discovery |
MalwareFruitFly | FruitFly looks for specific files and file types. |
| T1083 File and Directory Discovery |
MalwareAcidPour | AcidPour can identify specific files and directories within the Linux operating system corresponding with storage devices for follow-on wiping activity, similar to AcidRain. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.