Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareMESSAGETAP | MESSAGETAP checks for the existence of two configuration files (keyword_parm.txt and parm.txt) and attempts to read the files every 30 seconds. |
| T1083 File and Directory Discovery |
MalwareSUGARDUMP | SUGARDUMP can search for and collect data from specific Chrome, Opera, Microsoft Edge, and Firefox files, including any folders that have the string `Profile` in its name. |
| T1083 File and Directory Discovery |
MalwareSOUNDBITE | SOUNDBITE is capable of enumerating and manipulating files and directories. |
| T1083 File and Directory Discovery |
MalwareMoonWind | MoonWind has a command to return a directory listing for a specified directory. |
| T1083 File and Directory Discovery |
MalwareRyuk | Ryuk has enumerated files and folders on all mounted drives. |
| T1083 File and Directory Discovery |
MalwareCryptoistic | Cryptoistic can scan a directory to identify files for deletion. |
| T1083 File and Directory Discovery |
MalwareHermeticWiper | HermeticWiper can enumerate common folders such as My Documents, Desktop, and AppData. |
| T1083 File and Directory Discovery |
Malwareccf32 | ccf32 can parse collected files to identify specific file extensions. |
| T1083 File and Directory Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can exclude files associated with core system functions from encryption. |
| T1083 File and Directory Discovery |
MalwareZebrocy | Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the |
| T1083 File and Directory Discovery |
MalwareFinFisher | FinFisher enumerates directories and scans for certain files. |
| T1083 File and Directory Discovery |
MalwareLunarMail | LunarMail can search its staging directory for output files it has produced. |
| T1083 File and Directory Discovery |
MalwareCrossRAT | CrossRAT can list all files on a system. |
| T1083 File and Directory Discovery |
MalwareOwaAuth | OwaAuth has a command to list its directory and logical drives. |
| T1083 File and Directory Discovery |
MalwareCobalt Strike | Cobalt Strike can explore files on a compromised system. |
| T1083 File and Directory Discovery |
MalwareSUNBURST | SUNBURST had commands to enumerate files and directories. |
| T1083 File and Directory Discovery |
MalwareHotCroissant | HotCroissant has the ability to retrieve a list of files in a given directory as well as drives and drive types. |
| T1083 File and Directory Discovery |
MalwareREvil | REvil has the ability to identify specific files and directories that are not to be encrypted. |
| T1083 File and Directory Discovery |
MalwareSamurai | Samurai can use a specific module for file enumeration. |
| T1083 File and Directory Discovery |
MalwarePinchDuke | PinchDuke searches for files created within a certain timeframe and whose file extension matches a predefined list. |
| T1083 File and Directory Discovery |
MalwareUSBStealer | USBStealer searches victim drives for files matching certain extensions (“.skr”,“.pkr” or “.key”) or names. |
| T1083 File and Directory Discovery |
MalwareTaidoor | Taidoor can search for specific files. |
| T1083 File and Directory Discovery |
MalwareKivars | Kivars has the ability to list drives on the infected host. |
| T1083 File and Directory Discovery |
MalwareCaddyWiper | CaddyWiper can enumerate all files and directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareCyclops Blink | Cyclops Blink can use the Linux API `statvfs` to enumerate the current working directory. |
| T1083 File and Directory Discovery |
MalwareSeasalt | Seasalt has the capability to identify the drive type on a victim. |
| T1083 File and Directory Discovery |
MalwareTajMahal | TajMahal has the ability to index files from drives, user profiles, and removable drives. |
| T1083 File and Directory Discovery |
MalwarePLEAD | PLEAD has the ability to list drives and files on the compromised host. |
| T1083 File and Directory Discovery |
MalwareRaccoon Stealer | Raccoon Stealer identifies target files and directories for collection based on a configuration file. |
| T1083 File and Directory Discovery |
MalwareCardinal RAT | Cardinal RAT checks its current working directory upon execution and also contains watchdog functionality that ensures its executable is located in the correct path (else it will rewrite the payload). |
| T1083 File and Directory Discovery |
MalwarePisloader | Pisloader has commands to list drives on the victim machine and to list file information for a given directory. |
| T1083 File and Directory Discovery |
MalwareGoldenSpy | GoldenSpy has included a program "ExeProtector", which monitors for the existence of GoldenSpy on the infected system and redownloads if necessary. |
| T1083 File and Directory Discovery |
MalwareGold Dragon | Gold Dragon lists the directories for Desktop, program files, and the user’s recently accessed files. |
| T1083 File and Directory Discovery |
MalwareRamsay | Ramsay can collect directory and file lists. |
| T1083 File and Directory Discovery |
MalwareAshTag | The AshTag AshenOrchestrator component can enumerate files on victim hosts. |
| T1083 File and Directory Discovery |
MalwareMacMa | MacMa can search for a specific file on the compromised computer and can enumerate files in Desktop, Downloads, and Documents folders. |
| T1083 File and Directory Discovery |
MalwareFunnyDream | FunnyDream can identify files with .doc, .docx, .ppt, .pptx, .xls, .xlsx, and .pdf extensions and specific timestamps for collection. |
| T1083 File and Directory Discovery |
MalwareROADSWEEP | ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions. |
| T1083 File and Directory Discovery |
MalwareSUNSPOT | SUNSPOT enumerated the Orion software Visual Studio solution directory path. |
| T1083 File and Directory Discovery |
MalwareSysUpdate | SysUpdate can search files on a compromised host. |
| T1083 File and Directory Discovery |
MalwareOutSteel | OutSteel can search for specific file extensions, including zipped files. |
| T1083 File and Directory Discovery |
MalwareBackConfig | BackConfig has the ability to identify folders and files related to previous infections. |
| T1083 File and Directory Discovery |
MalwareANELLDR | ANELLDR can enumerate files in the current directory to search for encrypted payload files. |
| T1083 File and Directory Discovery |
MalwareKwampirs | Kwampirs collects a list of files and directories in C:\ with the command |
| T1083 File and Directory Discovery |
MalwareBoomBox | BoomBox can search for specific files and directories on a machine. |
| T1083 File and Directory Discovery |
MalwareLAMEHUG | LAMEHUG can target directories on victim machines for file collection. |
| T1083 File and Directory Discovery |
MalwareMango | Mango can enumerate the contents of current working or other specified directories. |
| T1083 File and Directory Discovery |
MalwareInnaputRAT | InnaputRAT enumerates directories and obtains file attributes on a system. |
| T1083 File and Directory Discovery |
MalwareGrimAgent | GrimAgent has the ability to enumerate files and directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareLookBack | LookBack can retrieve file listings from the victim machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.