Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareAzorult | Azorult can recursively search for files in folders and collects files from the desktop with certain extensions. |
| T1083 File and Directory Discovery |
MalwareBACKSPACE | BACKSPACE allows adversaries to search for files. |
| T1083 File and Directory Discovery |
MalwareZox | Zox can enumerate files on a compromised host. |
| T1083 File and Directory Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to gather the victim's current directory. |
| T1083 File and Directory Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list files and directories. |
| T1083 File and Directory Discovery |
MalwareStrifeWater | StrifeWater can enumerate files on a compromised host. |
| T1083 File and Directory Discovery |
MalwareWarzoneRAT | WarzoneRAT can enumerate directories on a compromise host. |
| T1083 File and Directory Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can enumerate files and directories. |
| T1083 File and Directory Discovery |
MalwareFALLCHILL | FALLCHILL can search files on a victim. |
| T1083 File and Directory Discovery |
ToolRemoteUtilities | RemoteUtilities can enumerate files and directories on a target machine. |
| T1083 File and Directory Discovery |
ToolDiskpart | If executed with elevated privileges, Diskpart can list all volumes, including virtual disks. |
| T1083 File and Directory Discovery |
ToolSliver | Sliver can enumerate files on a target system. |
| T1083 File and Directory Discovery |
ToolSILENTTRINITY | SILENTTRINITY has several modules, such as `ls.py`, `pwd.py`, and `recentFiles.py`, to enumerate directories and files. |
| T1083 File and Directory Discovery |
ToolEmpire | Empire includes various modules for finding files of interest on hosts and network shares. |
| T1083 File and Directory Discovery |
ToolPoshC2 | PoshC2 can enumerate files on the local file system and includes a module for enumerating recently accessed files. |
| T1083 File and Directory Discovery |
ToolRclone | Rclone can list files and directories with the `ls`, `lsd`, and `lsl` commands. |
| T1083 File and Directory Discovery |
ToolTruffleHog | TruffleHog has can browse and scan individual files and directories. |
| T1083 File and Directory Discovery |
ToolRemcos | Remcos can search for files on the infected machine. |
| T1083 File and Directory Discovery |
ToolImminent Monitor | Imminent Monitor has a dynamic debugging feature to check whether it is located in the %TEMP% directory, otherwise it copies itself there. |
| T1083 File and Directory Discovery |
ToolForfiles | Forfiles can be used to locate certain types of files/directories in a system.(ex: locate all files with a specific extension, name, and/or age) |
| T1083 File and Directory Discovery |
Toolcmd | cmd can be used to find files and directories with native functionality such as |
| T1083 File and Directory Discovery |
ToolCrackMapExec | CrackMapExec can discover specified filetypes and log files on a targeted system. |
| T1083 File and Directory Discovery |
ToolKoadic | Koadic can obtain a list of directories. |
| T1083 File and Directory Discovery |
ToolPupy | Pupy can walk through directories and recursively search for strings in files. |
| T1083 File and Directory Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify files containing environment variables, SSH keys, cloud credentials, access tokens, and cryptocurrency wallets. |
| T1083 File and Directory Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has enumerated home directories, file paths and files associated with storing or containing credentials and other secrets. |
| T1083 File and Directory Discovery |
MalwareCanisterWorm | CanisterWorm has discovered npm pathways and directories that frequently store .npmrc files to check for _authToken values. |
| T1083 File and Directory Discovery |
GroupShinyHunters | ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, ShinyHunters has read WebLogic server XML configurations files (config.xml). |
| T1083 File and Directory Discovery |
MalwareBADFLICK | BADFLICK has searched for files on the infected host. |
| T1087 Account Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal database user account tables to enumerate accounts and identify high-privilege accounts within compromised environments. |
| T1087 Account Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained a list of users and their roles from an Exchange server using `Get-ManagementRoleAssignment`. |
| T1087 Account Discovery |
GroupScattered Spider | Scattered Spider has identified vSphere administrator accounts. |
| T1087 Account Discovery |
GroupAquatic Panda | Aquatic Panda used the |
| T1087 Account Discovery |
GroupFIN13 | FIN13 has enumerated all users and their roles from a victim's main treasury system. |
| T1087 Account Discovery |
MalwareHavoc | Havoc can identify privileged user accounts on infected systems. |
| T1087 Account Discovery |
MalwareTONESHELL | TONESHELL included functionality to retrieve a list of user accounts. |
| T1087 Account Discovery |
MalwareWoody RAT | Woody RAT can identify administrator accounts on an infected machine. |
| T1087 Account Discovery |
MalwareXCSSET | XCSSET attempts to discover accounts from various locations such as a user's Evernote, AppleID, Telegram, Skype, and WeChat data. |
| T1087 Account Discovery |
ToolShimRatReporter | ShimRatReporter listed all non-privileged and privileged accounts available on the machine. |
| T1087.001 Local Account |
CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local.exe tool to view local account information. |
| T1087.001 Local Account |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net user` command to gather account information. |
| T1087.001 Local Account |
GroupAPT3 | APT3 has used a tool that can obtain info about local and global group users, power users, and administrators. |
| T1087.001 Local Account |
Groupadmin@338 | admin@338 actors used the following commands following exploitation of a machine with LOWBALL malware to enumerate user accounts: |
| T1087.001 Local Account |
GroupVolt Typhoon | Volt Typhoon has executed `net user` and `quser` to enumerate local account information. |
| T1087.001 Local Account |
GroupAPT41 | APT41 used built-in |
| T1087.001 Local Account |
GroupAPT32 | APT32 enumerated administrative users using the commands |
| T1087.001 Local Account |
GroupMoses Staff | Moses Staff has collected the administrator username from a compromised host. |
| T1087.001 Local Account |
GroupOilRig | OilRig has run |
| T1087.001 Local Account |
GroupKe3chang | Ke3chang performs account discovery using commands such as |
| T1087.001 Local Account |
GroupAPT1 | APT1 used the commands |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.