ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
MalwareAzorult

Azorult can recursively search for files in folders and collects files from the desktop with certain extensions.

T1083
File and Directory Discovery
MalwareBACKSPACE

BACKSPACE allows adversaries to search for files.

T1083
File and Directory Discovery
MalwareZox

Zox can enumerate files on a compromised host.

T1083
File and Directory Discovery
MalwareUPPERCUT

UPPERCUT has the capability to gather the victim's current directory.

T1083
File and Directory Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list files and directories.

T1083
File and Directory Discovery
MalwareStrifeWater

StrifeWater can enumerate files on a compromised host.

T1083
File and Directory Discovery
MalwareWarzoneRAT

WarzoneRAT can enumerate directories on a compromise host.

T1083
File and Directory Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can enumerate files and directories.

T1083
File and Directory Discovery
MalwareFALLCHILL

FALLCHILL can search files on a victim.

T1083
File and Directory Discovery
ToolRemoteUtilities

RemoteUtilities can enumerate files and directories on a target machine.

T1083
File and Directory Discovery
ToolDiskpart

If executed with elevated privileges, Diskpart can list all volumes, including virtual disks.

T1083
File and Directory Discovery
ToolSliver

Sliver can enumerate files on a target system.

T1083
File and Directory Discovery
ToolSILENTTRINITY

SILENTTRINITY has several modules, such as `ls.py`, `pwd.py`, and `recentFiles.py`, to enumerate directories and files.

T1083
File and Directory Discovery
ToolEmpire

Empire includes various modules for finding files of interest on hosts and network shares.

T1083
File and Directory Discovery
ToolPoshC2

PoshC2 can enumerate files on the local file system and includes a module for enumerating recently accessed files.

T1083
File and Directory Discovery
ToolRclone

Rclone can list files and directories with the `ls`, `lsd`, and `lsl` commands.

T1083
File and Directory Discovery
ToolTruffleHog

TruffleHog has can browse and scan individual files and directories.

T1083
File and Directory Discovery
ToolRemcos

Remcos can search for files on the infected machine.

T1083
File and Directory Discovery
ToolImminent Monitor

Imminent Monitor has a dynamic debugging feature to check whether it is located in the %TEMP% directory, otherwise it copies itself there.

T1083
File and Directory Discovery
ToolForfiles

Forfiles can be used to locate certain types of files/directories in a system.(ex: locate all files with a specific extension, name, and/or age)

T1083
File and Directory Discovery
Toolcmd

cmd can be used to find files and directories with native functionality such as dir commands.

T1083
File and Directory Discovery
ToolCrackMapExec

CrackMapExec can discover specified filetypes and log files on a targeted system.

T1083
File and Directory Discovery
ToolKoadic

Koadic can obtain a list of directories.

T1083
File and Directory Discovery
ToolPupy

Pupy can walk through directories and recursively search for strings in files.

T1083
File and Directory Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can identify files containing environment variables, SSH keys, cloud credentials, access tokens, and cryptocurrency wallets.

T1083
File and Directory Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has enumerated home directories, file paths and files associated with storing or containing credentials and other secrets.

T1083
File and Directory Discovery
MalwareCanisterWorm

CanisterWorm has discovered npm pathways and directories that frequently store .npmrc files to check for _authToken values.

T1083
File and Directory Discovery
GroupShinyHunters

ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, ShinyHunters has read WebLogic server XML configurations files (config.xml).

T1083
File and Directory Discovery
MalwareBADFLICK

BADFLICK has searched for files on the infected host.

T1087
Account Discovery
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal database user account tables to enumerate accounts and identify high-privilege accounts within compromised environments.

T1087
Account Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained a list of users and their roles from an Exchange server using `Get-ManagementRoleAssignment`.

T1087
Account Discovery
GroupScattered Spider

Scattered Spider has identified vSphere administrator accounts.

T1087
Account Discovery
GroupAquatic Panda

Aquatic Panda used the last command in Linux environments to identify recently logged-in users on victim machines.

T1087
Account Discovery
GroupFIN13

FIN13 has enumerated all users and their roles from a victim's main treasury system.

T1087
Account Discovery
MalwareHavoc

Havoc can identify privileged user accounts on infected systems.

T1087
Account Discovery
MalwareTONESHELL

TONESHELL included functionality to retrieve a list of user accounts.

T1087
Account Discovery
MalwareWoody RAT

Woody RAT can identify administrator accounts on an infected machine.

T1087
Account Discovery
MalwareXCSSET

XCSSET attempts to discover accounts from various locations such as a user's Evernote, AppleID, Telegram, Skype, and WeChat data.

T1087
Account Discovery
ToolShimRatReporter

ShimRatReporter listed all non-privileged and privileged accounts available on the machine.

T1087.001
Local Account
CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local.exe tool to view local account information.

T1087.001
Local Account
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net user` command to gather account information.

T1087.001
Local Account
GroupAPT3

APT3 has used a tool that can obtain info about local and global group users, power users, and administrators.

T1087.001
Local Account
Groupadmin@338

admin@338 actors used the following commands following exploitation of a machine with LOWBALL malware to enumerate user accounts: net user >> %temp%\download net user /domain >> %temp%\download

T1087.001
Local Account
GroupVolt Typhoon

Volt Typhoon has executed `net user` and `quser` to enumerate local account information.

T1087.001
Local Account
GroupAPT41

APT41 used built-in net commands to enumerate local administrator groups.

T1087.001
Local Account
GroupAPT32

APT32 enumerated administrative users using the commands net localgroup administrators.

T1087.001
Local Account
GroupMoses Staff

Moses Staff has collected the administrator username from a compromised host.

T1087.001
Local Account
GroupOilRig

OilRig has run net user, net user /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to get account listings on a victim.

T1087.001
Local Account
GroupKe3chang

Ke3chang performs account discovery using commands such as net localgroup administrators and net group "REDACTED" /domain on specific permissions groups.

T1087.001
Local Account
GroupAPT1

APT1 used the commands net localgroup,net user, and net group to find accounts on the system.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.