ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
MalwareDEATHRANSOM

DEATHRANSOM can use loop operations to enumerate directories on a compromised host.

T1083
File and Directory Discovery
MalwareClambling

Clambling can browse directories on a compromised host.

T1083
File and Directory Discovery
MalwareAkira

Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as GetFileAttributesW.

T1083
File and Directory Discovery
MalwareDarkGate

Some versions of DarkGate search for the hard-coded folder C:\Program Files\e Carte Bleue.

T1083
File and Directory Discovery
MalwareLockBit 3.0

LockBit 3.0 can exclude files associated with core system functions from encryption.

T1083
File and Directory Discovery
MalwareFoggyWeb

FoggyWeb's loader can check for the FoggyWeb backdoor .pri file on a compromised AD FS server.

T1083
File and Directory Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can check for the existence of files, including its own components, as well as retrieve a list of logical drives.

T1083
File and Directory Discovery
MalwareCreepyDrive

CreepyDrive can specify the local file path to upload files from.

T1083
File and Directory Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can search for files in directories.

T1083
File and Directory Discovery
MalwareElise

A variant of Elise executes dir C:\progra~1 when initially run.

T1083
File and Directory Discovery
MalwareUSBferry

USBferry can detect the victim's file or folder list.

T1083
File and Directory Discovery
MalwareWannaCry

WannaCry searches for variety of user files by file extension before encrypting them using RSA and AES, including Office, PDF, image, audio, video, source code, archive/compression format, and key and certificate files.

T1083
File and Directory Discovery
MalwareTSCookie

TSCookie has the ability to discover drive information on the infected host.

T1083
File and Directory Discovery
MalwareLatrodectus

Latrodectus can collect desktop filenames.

T1083
File and Directory Discovery
MalwareSaint Bot

Saint Bot can search a compromised host for specific files.

T1083
File and Directory Discovery
MalwareLODEINFO

LODEINFO has the ability to designate specific files and folders to encryption.

T1083
File and Directory Discovery
MalwareCharmPower

CharmPower can enumerate drives and list the contents of the C: drive on a victim's computer.

T1083
File and Directory Discovery
MalwareTYPEFRAME

TYPEFRAME can search directories for files on the victim’s machine.

T1083
File and Directory Discovery
Malware3PARA RAT

3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory.

T1083
File and Directory Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can use DirectoryList to enumerate files in a specified directory.

T1083
File and Directory Discovery
MalwareRoyal

Royal can identify specific files and directories to exclude from the encryption process.

T1083
File and Directory Discovery
MalwareUroburos

Uroburos can search for specific files on a compromised system.

T1083
File and Directory Discovery
MalwareMetamorfo

Metamorfo has searched the Program Files directories for specific folders and has searched for strings related to its mutexes.

T1083
File and Directory Discovery
MalwareSpica

Spica can list filesystem contents on targeted systems.

T1083
File and Directory Discovery
MalwareEmbargo

Embargo has searched for folders, subfolders and other networked or mounted drives for follow on encryption actions. Embargo has also iterated device volumes using `FindFirstVolumeW()` and `FindNextVolumeW()` functions and then calls the `GetVolumePathNamesForVolumeNameW()` function to retrieve a list of drive letters and mounted folder paths for each specified volume.

T1083
File and Directory Discovery
MalwareTrojan.Karagany

Trojan.Karagany can enumerate files and directories on a compromised host.

T1083
File and Directory Discovery
MalwareBandook

Bandook has a command to list files on a system.

T1083
File and Directory Discovery
MalwareTINYTYPHON

TINYTYPHON searches through the drive containing the OS, then all drive letters C through to Z, for documents matching certain extensions.

T1083
File and Directory Discovery
MalwareKONNI

A version of KONNI searches for filenames created with a previous version of the malware, suggesting different versions targeted the same victims and the versions may work together.

T1083
File and Directory Discovery
MalwareCORALDECK

CORALDECK searches for specified files.

T1083
File and Directory Discovery
MalwareSPACESHIP

SPACESHIP identifies files and directories for collection by searching for specific file extensions or file modification time.

T1083
File and Directory Discovery
MalwareBLUELIGHT

BLUELIGHT can enumerate files and collect associated metadata.

T1083
File and Directory Discovery
MalwareKGH_SPY

KGH_SPY can enumerate files and directories on a compromised host.

T1083
File and Directory Discovery
Malwaredown_new

down_new has the ability to list the directories on a compromised host.

T1083
File and Directory Discovery
MalwareIxeshe

Ixeshe can list file and directory information.

T1083
File and Directory Discovery
MalwareMicropsia

Micropsia can perform a recursive directory listing for all volume drives available on the victim's machine and can also fetch specific files by their paths.

T1083
File and Directory Discovery
MalwareRARSTONE

RARSTONE obtains installer properties from Uninstall Registry Key entries to obtain information about installed applications and how to uninstall certain applications.

T1083
File and Directory Discovery
MalwareBlack Basta

Black Basta can enumerate specific files for encryption.

T1083
File and Directory Discovery
Malware4H RAT

4H RAT has the capability to obtain file and directory listings.

T1083
File and Directory Discovery
MalwareAttor

Attor has a plugin that enumerates files with specific extensions on all hard disk drives and stores file information in encrypted log files.

T1083
File and Directory Discovery
MalwareMegaCortex

MegaCortex can parse the available drives and directories to determine which files to encrypt.

T1083
File and Directory Discovery
MalwareStreamEx

StreamEx has the ability to enumerate drive types.

T1083
File and Directory Discovery
MalwareBoxCaon

BoxCaon has searched for files on the system, such as documents located in the desktop folder.

T1083
File and Directory Discovery
MalwareNightClub

NightClub can use a file monitor to identify .lnk, .doc, .docx, .xls, .xslx, and .pdf files.

T1083
File and Directory Discovery
MalwareAkira _v2

Akira _v2 can target specific files and folders for encryption.

T1083
File and Directory Discovery
MalwareSDBbot

SDBbot has the ability to get directory listings or drive information on a compromised host.

T1083
File and Directory Discovery
MalwareRTM

RTM can check for specific files and directories associated with virtualization and malware analysis.

T1083
File and Directory Discovery
MalwareDerusbi

Derusbi is capable of obtaining directory, file, and drive listings.

T1083
File and Directory Discovery
MalwareBazar

Bazar can enumerate the victim's desktop.

T1083
File and Directory Discovery
MalwareBadPatch

BadPatch searches for files with specific file extensions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.