ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
MalwarePrestige

Prestige can traverse the file system to discover files to encrypt by identifying specific extensions defined in a hardcoded list.

T1083
File and Directory Discovery
MalwareInvisibleFerret

InvisibleFerret has identified specific directories and files for exfiltration using the `ssh_upload` command which contains subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr`, `sfind`. InvisibleFerret also has the capability to scan and upload files of interest from multiple OS systems through the use of scripts that check file names, file extensions, and avoids certain path names. InvisibleFerret has utilized the `findstr` on Windows or the macOS `find` commands to search for files of interest.

T1083
File and Directory Discovery
MalwareBankshot

Bankshot searches for files on the victim's machine.

T1083
File and Directory Discovery
MalwareSharpDisco

SharpDisco can identify recently opened files by using an LNK format parser to extract the original file path from LNK files found in either `%USERPROFILE%\Recent` (Windows XP) or `%APPDATA%\Microsoft\Windows\Recent` (newer Windows versions) .

T1083
File and Directory Discovery
MalwareStrongPity

StrongPity can parse the hard drive on a compromised host to identify specific file extensions.

T1083
File and Directory Discovery
MalwareWinMM

WinMM sets a WH_CBT Windows hook to search for and capture files on the victim.

T1083
File and Directory Discovery
MalwareNebulae

Nebulae can list files and directories on a compromised host.

T1083
File and Directory Discovery
MalwareAuditCred

AuditCred can search through folders and files on the system.

T1083
File and Directory Discovery
MalwareKasidet

Kasidet has the ability to search for a given filename on a victim.

T1083
File and Directory Discovery
MalwareOceanSalt

OceanSalt can extract drive information from the endpoint and search files on the system.

T1083
File and Directory Discovery
MalwarePlaycrypt

Playcrypt can avoid encrypting files with a .PLAY, .exe, .msi, .dll, .lnk, or .sys file extension.

T1083
File and Directory Discovery
MalwareBrave Prince

Brave Prince gathers file and directory information from the victim’s machine.

T1083
File and Directory Discovery
MalwareMedusa Ransomware

Medusa Ransomware has searched for files within the victim environment for encryption and exfiltration. Medusa Ransomware has also identified files associated with remote management services.

T1083
File and Directory Discovery
MalwareRainyDay

RainyDay can use a file exfiltration tool to collect recently changed files with specific extensions.

T1083
File and Directory Discovery
MalwareAppleSeed

AppleSeed has the ability to search for .txt, .ppt, .hwp, .pdf, and .doc files in specified directories.

T1083
File and Directory Discovery
MalwareNETWIRE

NETWIRE has the ability to search for files on the compromised host.

T1083
File and Directory Discovery
MalwareCosmicDuke

CosmicDuke searches attached and mounted drives for file extensions and keywords that match a predefined list.

T1083
File and Directory Discovery
MalwareGomir

Gomir collects information about directory and file structures, including total number of subdirectories, total number of files, and total size of files on infected systems.

T1083
File and Directory Discovery
MalwareAria-body

Aria-body has the ability to gather metadata from a file and to search for file and directory names.

T1083
File and Directory Discovery
MalwareBOLDMOVE

BOLDMOVE can list information of all files in the system recursively from the root directory or from a specified directory.

T1083
File and Directory Discovery
MalwareCrimson

Crimson contains commands to list files and directories, as well as search for files matching certain extensions from a defined list.

T1083
File and Directory Discovery
MalwareDUSTTRAP

DUSTTRAP can enumerate files and directories.

T1083
File and Directory Discovery
MalwareDynoWiper

DynoWiper has used the Microsoft Windows native `FindFirstFile()` and `FindNextFile()` to recursively enumerate directories and files on the system.

T1083
File and Directory Discovery
MalwareTurian

Turian can search for specific files and list directories.

T1083
File and Directory Discovery
MalwareMachete

Machete produces file listings in order to search for files to be exfiltrated.

T1083
File and Directory Discovery
MalwareAction RAT

Action RAT has the ability to collect drive and file information on an infected machine.

T1083
File and Directory Discovery
MalwareAvenger

Avenger has the ability to browse files in directories such as Program Files and the Desktop.

T1083
File and Directory Discovery
MalwarePrikormka

A module in Prikormka collects information about the paths, size, and creation time of files with specific file extensions, but not the actual content of the file.

T1083
File and Directory Discovery
MalwarePingPull

PingPull can enumerate storage volumes and folder contents of a compromised host.

T1083
File and Directory Discovery
MalwareDacls

Dacls can scan directories on a compromised host.

T1083
File and Directory Discovery
MalwareDropBook

DropBook can collect the names of all files and folders in the Program Files directories.

T1083
File and Directory Discovery
MalwareWoody RAT

Woody RAT can list all files and their associated attributes, including filename, type, owner, creation time, last access time, last write time, size, and permissions.

T1083
File and Directory Discovery
MalwareMafalda

Mafalda can search for files and directories.

T1083
File and Directory Discovery
MalwareELMER

ELMER is capable of performing directory listings.

T1083
File and Directory Discovery
MalwareSombRAT

SombRAT can execute enum to enumerate files in storage on a compromised system.

T1083
File and Directory Discovery
MalwareODAgent

ODAgent can identify the current working directory.

T1083
File and Directory Discovery
MalwareFLASHFLOOD

FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on the local system and removable media.

T1083
File and Directory Discovery
MalwareFYAnti

FYAnti can search the C:\Windows\Microsoft.NET\ directory for files of a specified size.

T1083
File and Directory Discovery
MalwareLoFiSe

LoFiSe can monitor the file system to identify files less than 6.4 MB in size with file extensions including .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .rtf, .tif, .odt, .ods, .odp, .eml, and .msg.

T1083
File and Directory Discovery
MalwareHOPLIGHT

HOPLIGHT has been observed enumerating system drives and partitions.

T1083
File and Directory Discovery
MalwareCuckoo Stealer

Cuckoo Stealer can search for files associated with specific applications.

T1083
File and Directory Discovery
MalwareMobileOrder

MobileOrder has a command to upload to its C2 server information about files on the victim mobile device, including SD card size, installed app list, SMS content, contacts, and calling history.

T1083
File and Directory Discovery
MalwareWastedLocker

WastedLocker can enumerate files and directories just prior to encryption.

T1083
File and Directory Discovery
MalwareInvisiMole

InvisiMole can list information about files in a directory and recently opened or used documents. InvisiMole can also search for specific files by supplied file mask.

T1083
File and Directory Discovery
MalwareP.A.S. Webshell

P.A.S. Webshell has the ability to list files and file characteristics including extension, size, ownership, and permissions.

T1083
File and Directory Discovery
MalwareVolgmer

Volgmer can list directories on a victim.

T1083
File and Directory Discovery
MalwareWINERACK

WINERACK can enumerate files and directories.

T1083
File and Directory Discovery
MalwareWhisperGate

WhisperGate can locate files based on hardcoded file extensions.

T1083
File and Directory Discovery
MalwareFruitFly

FruitFly looks for specific files and file types.

T1083
File and Directory Discovery
MalwareAcidPour

AcidPour can identify specific files and directories within the Linux operating system corresponding with storage devices for follow-on wiping activity, similar to AcidRain.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.