ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
MalwareMESSAGETAP

MESSAGETAP checks for the existence of two configuration files (keyword_parm.txt and parm.txt) and attempts to read the files every 30 seconds.

T1083
File and Directory Discovery
MalwareSUGARDUMP

SUGARDUMP can search for and collect data from specific Chrome, Opera, Microsoft Edge, and Firefox files, including any folders that have the string `Profile` in its name.

T1083
File and Directory Discovery
MalwareSOUNDBITE

SOUNDBITE is capable of enumerating and manipulating files and directories.

T1083
File and Directory Discovery
MalwareMoonWind

MoonWind has a command to return a directory listing for a specified directory.

T1083
File and Directory Discovery
MalwareRyuk

Ryuk has enumerated files and folders on all mounted drives.

T1083
File and Directory Discovery
MalwareCryptoistic

Cryptoistic can scan a directory to identify files for deletion.

T1083
File and Directory Discovery
MalwareHermeticWiper

HermeticWiper can enumerate common folders such as My Documents, Desktop, and AppData.

T1083
File and Directory Discovery
Malwareccf32

ccf32 can parse collected files to identify specific file extensions.

T1083
File and Directory Discovery
MalwareLockBit 2.0

LockBit 2.0 can exclude files associated with core system functions from encryption.

T1083
File and Directory Discovery
MalwareZebrocy

Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the echo %APPDATA% command to list the contents of the directory. Zebrocy can obtain the current execution path as well as perform drive enumeration.

T1083
File and Directory Discovery
MalwareFinFisher

FinFisher enumerates directories and scans for certain files.

T1083
File and Directory Discovery
MalwareLunarMail

LunarMail can search its staging directory for output files it has produced.

T1083
File and Directory Discovery
MalwareCrossRAT

CrossRAT can list all files on a system.

T1083
File and Directory Discovery
MalwareOwaAuth

OwaAuth has a command to list its directory and logical drives.

T1083
File and Directory Discovery
MalwareCobalt Strike

Cobalt Strike can explore files on a compromised system.

T1083
File and Directory Discovery
MalwareSUNBURST

SUNBURST had commands to enumerate files and directories.

T1083
File and Directory Discovery
MalwareHotCroissant

HotCroissant has the ability to retrieve a list of files in a given directory as well as drives and drive types.

T1083
File and Directory Discovery
MalwareREvil

REvil has the ability to identify specific files and directories that are not to be encrypted.

T1083
File and Directory Discovery
MalwareSamurai

Samurai can use a specific module for file enumeration.

T1083
File and Directory Discovery
MalwarePinchDuke

PinchDuke searches for files created within a certain timeframe and whose file extension matches a predefined list.

T1083
File and Directory Discovery
MalwareUSBStealer

USBStealer searches victim drives for files matching certain extensions (“.skr”,“.pkr” or “.key”) or names.

T1083
File and Directory Discovery
MalwareTaidoor

Taidoor can search for specific files.

T1083
File and Directory Discovery
MalwareKivars

Kivars has the ability to list drives on the infected host.

T1083
File and Directory Discovery
MalwareCaddyWiper

CaddyWiper can enumerate all files and directories on a compromised host.

T1083
File and Directory Discovery
MalwareCyclops Blink

Cyclops Blink can use the Linux API `statvfs` to enumerate the current working directory.

T1083
File and Directory Discovery
MalwareSeasalt

Seasalt has the capability to identify the drive type on a victim.

T1083
File and Directory Discovery
MalwareTajMahal

TajMahal has the ability to index files from drives, user profiles, and removable drives.

T1083
File and Directory Discovery
MalwarePLEAD

PLEAD has the ability to list drives and files on the compromised host.

T1083
File and Directory Discovery
MalwareRaccoon Stealer

Raccoon Stealer identifies target files and directories for collection based on a configuration file.

T1083
File and Directory Discovery
MalwareCardinal RAT

Cardinal RAT checks its current working directory upon execution and also contains watchdog functionality that ensures its executable is located in the correct path (else it will rewrite the payload).

T1083
File and Directory Discovery
MalwarePisloader

Pisloader has commands to list drives on the victim machine and to list file information for a given directory.

T1083
File and Directory Discovery
MalwareGoldenSpy

GoldenSpy has included a program "ExeProtector", which monitors for the existence of GoldenSpy on the infected system and redownloads if necessary.

T1083
File and Directory Discovery
MalwareGold Dragon

Gold Dragon lists the directories for Desktop, program files, and the user’s recently accessed files.

T1083
File and Directory Discovery
MalwareRamsay

Ramsay can collect directory and file lists.

T1083
File and Directory Discovery
MalwareAshTag

The AshTag AshenOrchestrator component can enumerate files on victim hosts.

T1083
File and Directory Discovery
MalwareMacMa

MacMa can search for a specific file on the compromised computer and can enumerate files in Desktop, Downloads, and Documents folders.

T1083
File and Directory Discovery
MalwareFunnyDream

FunnyDream can identify files with .doc, .docx, .ppt, .pptx, .xls, .xlsx, and .pdf extensions and specific timestamps for collection.

T1083
File and Directory Discovery
MalwareROADSWEEP

ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions.

T1083
File and Directory Discovery
MalwareSUNSPOT

SUNSPOT enumerated the Orion software Visual Studio solution directory path.

T1083
File and Directory Discovery
MalwareSysUpdate

SysUpdate can search files on a compromised host.

T1083
File and Directory Discovery
MalwareOutSteel

OutSteel can search for specific file extensions, including zipped files.

T1083
File and Directory Discovery
MalwareBackConfig

BackConfig has the ability to identify folders and files related to previous infections.

T1083
File and Directory Discovery
MalwareANELLDR

ANELLDR can enumerate files in the current directory to search for encrypted payload files.

T1083
File and Directory Discovery
MalwareKwampirs

Kwampirs collects a list of files and directories in C:\ with the command dir /s /a c:\ >> "C:\windows\TEMP\[RANDOM].tmp".

T1083
File and Directory Discovery
MalwareBoomBox

BoomBox can search for specific files and directories on a machine.

T1083
File and Directory Discovery
MalwareLAMEHUG

LAMEHUG can target directories on victim machines for file collection.

T1083
File and Directory Discovery
MalwareMango

Mango can enumerate the contents of current working or other specified directories.

T1083
File and Directory Discovery
MalwareInnaputRAT

InnaputRAT enumerates directories and obtains file attributes on a system.

T1083
File and Directory Discovery
MalwareGrimAgent

GrimAgent has the ability to enumerate files and directories on a compromised host.

T1083
File and Directory Discovery
MalwareLookBack

LookBack can retrieve file listings from the victim machine.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.