Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareDEATHRANSOM | DEATHRANSOM can use loop operations to enumerate directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareClambling | Clambling can browse directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareAkira | Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as |
| T1083 File and Directory Discovery |
MalwareDarkGate | Some versions of DarkGate search for the hard-coded folder |
| T1083 File and Directory Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can exclude files associated with core system functions from encryption. |
| T1083 File and Directory Discovery |
MalwareFoggyWeb | FoggyWeb's loader can check for the FoggyWeb backdoor .pri file on a compromised AD FS server. |
| T1083 File and Directory Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can check for the existence of files, including its own components, as well as retrieve a list of logical drives. |
| T1083 File and Directory Discovery |
MalwareCreepyDrive | CreepyDrive can specify the local file path to upload files from. |
| T1083 File and Directory Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can search for files in directories. |
| T1083 File and Directory Discovery |
MalwareElise | A variant of Elise executes |
| T1083 File and Directory Discovery |
MalwareUSBferry | USBferry can detect the victim's file or folder list. |
| T1083 File and Directory Discovery |
MalwareWannaCry | WannaCry searches for variety of user files by file extension before encrypting them using RSA and AES, including Office, PDF, image, audio, video, source code, archive/compression format, and key and certificate files. |
| T1083 File and Directory Discovery |
MalwareTSCookie | TSCookie has the ability to discover drive information on the infected host. |
| T1083 File and Directory Discovery |
MalwareLatrodectus | Latrodectus can collect desktop filenames. |
| T1083 File and Directory Discovery |
MalwareSaint Bot | Saint Bot can search a compromised host for specific files. |
| T1083 File and Directory Discovery |
MalwareLODEINFO | LODEINFO has the ability to designate specific files and folders to encryption. |
| T1083 File and Directory Discovery |
MalwareCharmPower | CharmPower can enumerate drives and list the contents of the C: drive on a victim's computer. |
| T1083 File and Directory Discovery |
MalwareTYPEFRAME | TYPEFRAME can search directories for files on the victim’s machine. |
| T1083 File and Directory Discovery |
Malware3PARA RAT | 3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory. |
| T1083 File and Directory Discovery |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can use |
| T1083 File and Directory Discovery |
MalwareRoyal | Royal can identify specific files and directories to exclude from the encryption process. |
| T1083 File and Directory Discovery |
MalwareUroburos | Uroburos can search for specific files on a compromised system. |
| T1083 File and Directory Discovery |
MalwareMetamorfo | Metamorfo has searched the Program Files directories for specific folders and has searched for strings related to its mutexes. |
| T1083 File and Directory Discovery |
MalwareSpica | Spica can list filesystem contents on targeted systems. |
| T1083 File and Directory Discovery |
MalwareEmbargo | Embargo has searched for folders, subfolders and other networked or mounted drives for follow on encryption actions. Embargo has also iterated device volumes using `FindFirstVolumeW()` and `FindNextVolumeW()` functions and then calls the `GetVolumePathNamesForVolumeNameW()` function to retrieve a list of drive letters and mounted folder paths for each specified volume. |
| T1083 File and Directory Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can enumerate files and directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareBandook | Bandook has a command to list files on a system. |
| T1083 File and Directory Discovery |
MalwareTINYTYPHON | TINYTYPHON searches through the drive containing the OS, then all drive letters C through to Z, for documents matching certain extensions. |
| T1083 File and Directory Discovery |
MalwareKONNI | A version of KONNI searches for filenames created with a previous version of the malware, suggesting different versions targeted the same victims and the versions may work together. |
| T1083 File and Directory Discovery |
MalwareCORALDECK | CORALDECK searches for specified files. |
| T1083 File and Directory Discovery |
MalwareSPACESHIP | SPACESHIP identifies files and directories for collection by searching for specific file extensions or file modification time. |
| T1083 File and Directory Discovery |
MalwareBLUELIGHT | BLUELIGHT can enumerate files and collect associated metadata. |
| T1083 File and Directory Discovery |
MalwareKGH_SPY | KGH_SPY can enumerate files and directories on a compromised host. |
| T1083 File and Directory Discovery |
Malwaredown_new | down_new has the ability to list the directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareIxeshe | Ixeshe can list file and directory information. |
| T1083 File and Directory Discovery |
MalwareMicropsia | Micropsia can perform a recursive directory listing for all volume drives available on the victim's machine and can also fetch specific files by their paths. |
| T1083 File and Directory Discovery |
MalwareRARSTONE | RARSTONE obtains installer properties from Uninstall Registry Key entries to obtain information about installed applications and how to uninstall certain applications. |
| T1083 File and Directory Discovery |
MalwareBlack Basta | Black Basta can enumerate specific files for encryption. |
| T1083 File and Directory Discovery |
Malware4H RAT | 4H RAT has the capability to obtain file and directory listings. |
| T1083 File and Directory Discovery |
MalwareAttor | Attor has a plugin that enumerates files with specific extensions on all hard disk drives and stores file information in encrypted log files. |
| T1083 File and Directory Discovery |
MalwareMegaCortex | MegaCortex can parse the available drives and directories to determine which files to encrypt. |
| T1083 File and Directory Discovery |
MalwareStreamEx | StreamEx has the ability to enumerate drive types. |
| T1083 File and Directory Discovery |
MalwareBoxCaon | BoxCaon has searched for files on the system, such as documents located in the desktop folder. |
| T1083 File and Directory Discovery |
MalwareNightClub | NightClub can use a file monitor to identify .lnk, .doc, .docx, .xls, .xslx, and .pdf files. |
| T1083 File and Directory Discovery |
MalwareAkira _v2 | Akira _v2 can target specific files and folders for encryption. |
| T1083 File and Directory Discovery |
MalwareSDBbot | SDBbot has the ability to get directory listings or drive information on a compromised host. |
| T1083 File and Directory Discovery |
MalwareRTM | RTM can check for specific files and directories associated with virtualization and malware analysis. |
| T1083 File and Directory Discovery |
MalwareDerusbi | Derusbi is capable of obtaining directory, file, and drive listings. |
| T1083 File and Directory Discovery |
MalwareBazar | Bazar can enumerate the victim's desktop. |
| T1083 File and Directory Discovery |
MalwareBadPatch | BadPatch searches for files with specific file extensions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.