Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareClop | Clop has searched folders and subfolders for files to encrypt. |
| T1083 File and Directory Discovery |
MalwareLokibot | Lokibot can search for specific files on an infected host. |
| T1083 File and Directory Discovery |
MalwarePoetRAT | PoetRAT has the ability to list files upon receiving the |
| T1083 File and Directory Discovery |
MalwareCHOPSTICK | An older version of CHOPSTICK has a module that monitors all mounted volumes for files with the extensions .doc, .docx, .pgp, .gpg, .m2f, or .m2o. |
| T1083 File and Directory Discovery |
MalwareStealBit | StealBit can be configured to exfiltrate specific file types. |
| T1083 File and Directory Discovery |
MalwareZxShell | ZxShell has a command to open a file manager and explorer on the system. |
| T1083 File and Directory Discovery |
MalwareNDiskMonitor | NDiskMonitor can obtain a list of all files and directories as well as logical drives. |
| T1083 File and Directory Discovery |
MalwareDDKONG | DDKONG lists files on the victim’s machine. |
| T1083 File and Directory Discovery |
MalwarePenquin | Penquin can use the command code |
| T1083 File and Directory Discovery |
MalwareBabyShark | BabyShark has used |
| T1083 File and Directory Discovery |
MalwareCannon | Cannon can obtain victim drive information as well as a list of folders in C:\Program Files. |
| T1083 File and Directory Discovery |
MalwareWinnti for Windows | Winnti for Windows can check for the presence of specific files prior to moving to the next phase of execution. |
| T1083 File and Directory Discovery |
MalwareTroll Stealer | Troll Stealer can enumerate and collect items from local drives and folders. |
| T1083 File and Directory Discovery |
MalwareBLACKCOFFEE | BLACKCOFFEE has the capability to enumerate files. |
| T1083 File and Directory Discovery |
MalwareKinsing | Kinsing has used the find command to search for specific files. |
| T1083 File and Directory Discovery |
MalwarenjRAT | njRAT can browse file systems using a file manager module. |
| T1083 File and Directory Discovery |
MalwareZIPLINE | ZIPLINE can find and append specific files on Ivanti Connect Secure VPNs based upon received commands. |
| T1083 File and Directory Discovery |
MalwareChChes | ChChes collects the victim's %TEMP% directory path and version of Internet Explorer. |
| T1083 File and Directory Discovery |
MalwareManjusaka | Manjusaka can gather information about specific files on the victim system. |
| T1083 File and Directory Discovery |
MalwareIceApple | The IceApple Directory Lister module can list information about files and directories including creation time, last write time, name, and size. |
| T1083 File and Directory Discovery |
MalwareJPIN | JPIN can enumerate drives and their types. It can also change file permissions using cacls.exe. |
| T1083 File and Directory Discovery |
MalwaremetaMain | metaMain can recursively enumerate files in an operator-provided directory. |
| T1083 File and Directory Discovery |
MalwareSideTwist | SideTwist has the ability to search for specific files. |
| T1083 File and Directory Discovery |
MalwarePsylo | Psylo has commands to enumerate all storage devices and to find all files that start with a particular string. |
| T1083 File and Directory Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor has the ability to search the compromised host for files. |
| T1083 File and Directory Discovery |
MalwareHTTPBrowser | HTTPBrowser is capable of listing files, folders, and drives on a victim. |
| T1083 File and Directory Discovery |
MalwareLunarWeb | LunarWeb has the ability to retrieve directory listings. |
| T1083 File and Directory Discovery |
MalwareXCSSET | XCSSET has used `mdfind` to enumerate a list of apps known to grant screen sharing permissions and leverages a module to run the command `ls -la ~/Desktop`. |
| T1083 File and Directory Discovery |
MalwareOctopus | Octopus can collect information on the Windows directory and searches for compressed RAR files on the host. |
| T1083 File and Directory Discovery |
MalwareKillDisk | KillDisk has used the |
| T1083 File and Directory Discovery |
MalwareQilin | Qilin can exclude specific directories and files from encryption. |
| T1083 File and Directory Discovery |
MalwareSoreFang | SoreFang has the ability to list directories. |
| T1083 File and Directory Discovery |
MalwareIndustroyer | Industroyer’s data wiper component enumerates specific files on all the Windows drives. |
| T1083 File and Directory Discovery |
MalwareLazyWiper | LazyWiper can specifically target multiple files by extension including: .rar, .tar.gz, .zip, .7z, .json, .bcp, .bak, .gho, .erf, .edb, .onepkg, .pst, and .ldiff. |
| T1083 File and Directory Discovery |
MalwarePcexter | Pcexter has the ability to search for files in specified directories. |
| T1083 File and Directory Discovery |
MalwarePasam | Pasam creates a backdoor through which remote attackers can retrieve lists of files. |
| T1083 File and Directory Discovery |
MalwareBADNEWS | BADNEWS identifies files with certain extensions from USB devices, then copies them to a predefined directory. |
| T1083 File and Directory Discovery |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can list contents of drives and search for files. |
| T1083 File and Directory Discovery |
MalwareRemexi | Remexi searches for files on the system. |
| T1083 File and Directory Discovery |
MalwareQakBot | QakBot can identify whether it has been run previously on a host by checking for a specified folder. |
| T1083 File and Directory Discovery |
MalwareCookieMiner | CookieMiner has looked for files in the user's home directory with "wallet" in their name using |
| T1083 File and Directory Discovery |
MalwareGelsemium | Gelsemium can retrieve data from specific Windows directories, as well as open random files as part of Virtualization/Sandbox Evasion. |
| T1083 File and Directory Discovery |
MalwarejRAT | jRAT can browse file systems. |
| T1083 File and Directory Discovery |
MalwareOSX/Shlayer | OSX/Shlayer has used the command |
| T1083 File and Directory Discovery |
MalwareDenis | Denis has several commands to search directories for files. |
| T1083 File and Directory Discovery |
MalwareINC Ransomware | INC Ransomware can receive command line arguments to encrypt specific files and directories. |
| T1083 File and Directory Discovery |
MalwareSplatCloak | SplatCloak has used Windows API to identify files associated with Windows Defender and Kaspersky. |
| T1083 File and Directory Discovery |
MalwareFIVEHANDS | FIVEHANDS has the ability to enumerate files on a compromised host in order to encrypt files with specific extensions. |
| T1083 File and Directory Discovery |
MalwareAutoIt backdoor | AutoIt backdoor is capable of identifying documents on the victim with the following extensions: .doc; .pdf, .csv, .ppt, .docx, .pst, .xls, .xlsx, .pptx, and .jpeg. |
| T1083 File and Directory Discovery |
MalwareDtrack | Dtrack can list files on available disk volumes. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.