Real-world descriptions of how a group, tool or campaign used a technique.
308 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareCrimson | Crimson contains commands to list files and directories, as well as search for files matching certain extensions from a defined list. |
| T1083 File and Directory Discovery |
MalwareDUSTTRAP | DUSTTRAP can enumerate files and directories. |
| T1083 File and Directory Discovery |
MalwareDynoWiper | DynoWiper has used the Microsoft Windows native `FindFirstFile()` and `FindNextFile()` to recursively enumerate directories and files on the system. |
| T1083 File and Directory Discovery |
MalwareTurian | Turian can search for specific files and list directories. |
| T1083 File and Directory Discovery |
MalwareMachete | Machete produces file listings in order to search for files to be exfiltrated. |
| T1083 File and Directory Discovery |
MalwareAction RAT | Action RAT has the ability to collect drive and file information on an infected machine. |
| T1083 File and Directory Discovery |
MalwareAvenger | Avenger has the ability to browse files in directories such as Program Files and the Desktop. |
| T1083 File and Directory Discovery |
MalwarePrikormka | A module in Prikormka collects information about the paths, size, and creation time of files with specific file extensions, but not the actual content of the file. |
| T1083 File and Directory Discovery |
MalwarePingPull | PingPull can enumerate storage volumes and folder contents of a compromised host. |
| T1083 File and Directory Discovery |
MalwareDacls | Dacls can scan directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareDropBook | DropBook can collect the names of all files and folders in the Program Files directories. |
| T1083 File and Directory Discovery |
MalwareWoody RAT | Woody RAT can list all files and their associated attributes, including filename, type, owner, creation time, last access time, last write time, size, and permissions. |
| T1083 File and Directory Discovery |
MalwareMafalda | Mafalda can search for files and directories. |
| T1083 File and Directory Discovery |
MalwareELMER | ELMER is capable of performing directory listings. |
| T1083 File and Directory Discovery |
MalwareSombRAT | SombRAT can execute |
| T1083 File and Directory Discovery |
MalwareODAgent | ODAgent can identify the current working directory. |
| T1083 File and Directory Discovery |
MalwareFLASHFLOOD | FLASHFLOOD searches for interesting files (either a default or customized set of file extensions) on the local system and removable media. |
| T1083 File and Directory Discovery |
MalwareFYAnti | FYAnti can search the |
| T1083 File and Directory Discovery |
MalwareLoFiSe | LoFiSe can monitor the file system to identify files less than 6.4 MB in size with file extensions including .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pdf, .rtf, .tif, .odt, .ods, .odp, .eml, and .msg. |
| T1083 File and Directory Discovery |
MalwareHOPLIGHT | HOPLIGHT has been observed enumerating system drives and partitions. |
| T1083 File and Directory Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can search for files associated with specific applications. |
| T1083 File and Directory Discovery |
MalwareMobileOrder | MobileOrder has a command to upload to its C2 server information about files on the victim mobile device, including SD card size, installed app list, SMS content, contacts, and calling history. |
| T1083 File and Directory Discovery |
MalwareWastedLocker | WastedLocker can enumerate files and directories just prior to encryption. |
| T1083 File and Directory Discovery |
MalwareInvisiMole | InvisiMole can list information about files in a directory and recently opened or used documents. InvisiMole can also search for specific files by supplied file mask. |
| T1083 File and Directory Discovery |
MalwareP.A.S. Webshell | P.A.S. Webshell has the ability to list files and file characteristics including extension, size, ownership, and permissions. |
| T1083 File and Directory Discovery |
MalwareVolgmer | Volgmer can list directories on a victim. |
| T1083 File and Directory Discovery |
MalwareWINERACK | WINERACK can enumerate files and directories. |
| T1083 File and Directory Discovery |
MalwareWhisperGate | WhisperGate can locate files based on hardcoded file extensions. |
| T1083 File and Directory Discovery |
MalwareFruitFly | FruitFly looks for specific files and file types. |
| T1083 File and Directory Discovery |
MalwareAcidPour | AcidPour can identify specific files and directories within the Linux operating system corresponding with storage devices for follow-on wiping activity, similar to AcidRain. |
| T1083 File and Directory Discovery |
MalwareSkidmap | Skidmap has checked for the existence of specific files including |
| T1083 File and Directory Discovery |
MalwareOkrum | Okrum has used DriveLetterView to enumerate drive information. |
| T1083 File and Directory Discovery |
MalwareConti | Conti can discover files on a local system. |
| T1083 File and Directory Discovery |
MalwareSameCoin | SameCoin can list all system files and can avoid wiping specific directories such as Program Files, Windows, and Users. |
| T1083 File and Directory Discovery |
MalwareRaspberry Robin | Raspberry Robin will check to see if the initial executing script is located on the user's Desktop as an anti-analysis check. |
| T1083 File and Directory Discovery |
MalwareMispadu | Mispadu searches for various filesystem paths to determine what banking applications are installed on the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareMegazord | Megazord can ignore specified directories for encryption. |
| T1083 File and Directory Discovery |
MalwareDiavol | Diavol has a command to traverse the files and directories in a given path. |
| T1083 File and Directory Discovery |
MalwareDoki | Doki has resolved the path of a process PID to use as a script argument. |
| T1083 File and Directory Discovery |
MalwareSiloscape | Siloscape searches for the Kubernetes config file and other related files using a regular expression. |
| T1083 File and Directory Discovery |
MalwareBlackCat | BlackCat can enumerate files for encryption. |
| T1083 File and Directory Discovery |
MalwareFysbis | Fysbis has the ability to search for files. |
| T1083 File and Directory Discovery |
MalwareMarkiRAT | MarkiRAT can look for files carrying specific extensions such as: .rtf, .doc, .docx, .xls, .xlsx, .ppt, .pptx, .pps, .ppsx, .txt, .gpg, .pkr, .kdbx, .key, and .jpb. |
| T1083 File and Directory Discovery |
MalwareKazuar | Kazuar finds a specified directory, lists the files and metadata about those files. |
| T1083 File and Directory Discovery |
MalwareNETEAGLE | NETEAGLE allows adversaries to enumerate and modify the infected host's file system. It supports searching for directories, creating directories, listing directory contents, reading and writing to files, retrieving file attributes, and retrieving volume information. |
| T1083 File and Directory Discovery |
MalwarePOORAIM | POORAIM can conduct file browsing. |
| T1083 File and Directory Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has the ability to enumerate directories for files that match a set list. |
| T1083 File and Directory Discovery |
MalwareFatDuke | FatDuke can enumerate directories on target machines. |
| T1083 File and Directory Discovery |
MalwareBlackEnergy | BlackEnergy gathers a list of installed apps from the uninstall program Registry. It also gathers registered mail, browser, and instant messaging clients from the Registry. BlackEnergy has searched for given file types. |
| T1083 File and Directory Discovery |
MalwarezwShell | zwShell can browse the file system. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.