ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
MalwareClop

Clop has searched folders and subfolders for files to encrypt.

T1083
File and Directory Discovery
MalwareLokibot

Lokibot can search for specific files on an infected host.

T1083
File and Directory Discovery
MalwarePoetRAT

PoetRAT has the ability to list files upon receiving the ls command from C2.

T1083
File and Directory Discovery
MalwareCHOPSTICK

An older version of CHOPSTICK has a module that monitors all mounted volumes for files with the extensions .doc, .docx, .pgp, .gpg, .m2f, or .m2o.

T1083
File and Directory Discovery
MalwareStealBit

StealBit can be configured to exfiltrate specific file types.

T1083
File and Directory Discovery
MalwareZxShell

ZxShell has a command to open a file manager and explorer on the system.

T1083
File and Directory Discovery
MalwareNDiskMonitor

NDiskMonitor can obtain a list of all files and directories as well as logical drives.

T1083
File and Directory Discovery
MalwareDDKONG

DDKONG lists files on the victim’s machine.

T1083
File and Directory Discovery
MalwarePenquin

Penquin can use the command code do_vslist to send file names, size, and status to C2.

T1083
File and Directory Discovery
MalwareBabyShark

BabyShark has used dir to search for "programfiles" and "appdata".

T1083
File and Directory Discovery
MalwareCannon

Cannon can obtain victim drive information as well as a list of folders in C:\Program Files.

T1083
File and Directory Discovery
MalwareWinnti for Windows

Winnti for Windows can check for the presence of specific files prior to moving to the next phase of execution.

T1083
File and Directory Discovery
MalwareTroll Stealer

Troll Stealer can enumerate and collect items from local drives and folders.

T1083
File and Directory Discovery
MalwareBLACKCOFFEE

BLACKCOFFEE has the capability to enumerate files.

T1083
File and Directory Discovery
MalwareKinsing

Kinsing has used the find command to search for specific files.

T1083
File and Directory Discovery
MalwarenjRAT

njRAT can browse file systems using a file manager module.

T1083
File and Directory Discovery
MalwareZIPLINE

ZIPLINE can find and append specific files on Ivanti Connect Secure VPNs based upon received commands.

T1083
File and Directory Discovery
MalwareChChes

ChChes collects the victim's %TEMP% directory path and version of Internet Explorer.

T1083
File and Directory Discovery
MalwareManjusaka

Manjusaka can gather information about specific files on the victim system.

T1083
File and Directory Discovery
MalwareIceApple

The IceApple Directory Lister module can list information about files and directories including creation time, last write time, name, and size.

T1083
File and Directory Discovery
MalwareJPIN

JPIN can enumerate drives and their types. It can also change file permissions using cacls.exe.

T1083
File and Directory Discovery
MalwaremetaMain

metaMain can recursively enumerate files in an operator-provided directory.

T1083
File and Directory Discovery
MalwareSideTwist

SideTwist has the ability to search for specific files.

T1083
File and Directory Discovery
MalwarePsylo

Psylo has commands to enumerate all storage devices and to find all files that start with a particular string.

T1083
File and Directory Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor has the ability to search the compromised host for files.

T1083
File and Directory Discovery
MalwareHTTPBrowser

HTTPBrowser is capable of listing files, folders, and drives on a victim.

T1083
File and Directory Discovery
MalwareLunarWeb

LunarWeb has the ability to retrieve directory listings.

T1083
File and Directory Discovery
MalwareXCSSET

XCSSET has used `mdfind` to enumerate a list of apps known to grant screen sharing permissions and leverages a module to run the command `ls -la ~/Desktop`.

T1083
File and Directory Discovery
MalwareOctopus

Octopus can collect information on the Windows directory and searches for compressed RAR files on the host.

T1083
File and Directory Discovery
MalwareKillDisk

KillDisk has used the FindNextFile command as part of its file deletion process.

T1083
File and Directory Discovery
MalwareQilin

Qilin can exclude specific directories and files from encryption.

T1083
File and Directory Discovery
MalwareSoreFang

SoreFang has the ability to list directories.

T1083
File and Directory Discovery
MalwareIndustroyer

Industroyer’s data wiper component enumerates specific files on all the Windows drives.

T1083
File and Directory Discovery
MalwareLazyWiper

LazyWiper can specifically target multiple files by extension including: .rar, .tar.gz, .zip, .7z, .json, .bcp, .bak, .gho, .erf, .edb, .onepkg, .pst, and .ldiff.

T1083
File and Directory Discovery
MalwarePcexter

Pcexter has the ability to search for files in specified directories.

T1083
File and Directory Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve lists of files.

T1083
File and Directory Discovery
MalwareBADNEWS

BADNEWS identifies files with certain extensions from USB devices, then copies them to a predefined directory.

T1083
File and Directory Discovery
MalwareLinfo

Linfo creates a backdoor through which remote attackers can list contents of drives and search for files.

T1083
File and Directory Discovery
MalwareRemexi

Remexi searches for files on the system.

T1083
File and Directory Discovery
MalwareQakBot

QakBot can identify whether it has been run previously on a host by checking for a specified folder.

T1083
File and Directory Discovery
MalwareCookieMiner

CookieMiner has looked for files in the user's home directory with "wallet" in their name using find.

T1083
File and Directory Discovery
MalwareGelsemium

Gelsemium can retrieve data from specific Windows directories, as well as open random files as part of Virtualization/Sandbox Evasion.

T1083
File and Directory Discovery
MalwarejRAT

jRAT can browse file systems.

T1083
File and Directory Discovery
MalwareOSX/Shlayer

OSX/Shlayer has used the command appDir="$(dirname $(dirname "$currentDir"))" and $(dirname "$(pwd -P)") to construct installation paths.

T1083
File and Directory Discovery
MalwareDenis

Denis has several commands to search directories for files.

T1083
File and Directory Discovery
MalwareINC Ransomware

INC Ransomware can receive command line arguments to encrypt specific files and directories.

T1083
File and Directory Discovery
MalwareSplatCloak

SplatCloak has used Windows API to identify files associated with Windows Defender and Kaspersky.

T1083
File and Directory Discovery
MalwareFIVEHANDS

FIVEHANDS has the ability to enumerate files on a compromised host in order to encrypt files with specific extensions.

T1083
File and Directory Discovery
MalwareAutoIt backdoor

AutoIt backdoor is capable of identifying documents on the victim with the following extensions: .doc; .pdf, .csv, .ppt, .docx, .pst, .xls, .xlsx, .pptx, and .jpeg.

T1083
File and Directory Discovery
MalwareDtrack

Dtrack can list files on available disk volumes.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.