Real-world descriptions of how a group, tool or campaign used a technique.
308 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareRising Sun | Rising Sun can enumerate information about files from the infected system, including file size, attributes, creation time, last access time, and write time. Rising Sun can enumerate the compilation timestamp of Windows executable files. |
| T1083 File and Directory Discovery |
MalwareNotPetya | NotPetya searches for files ending with dozens of different file extensions prior to encryption. |
| T1083 File and Directory Discovery |
MalwareShimRat | ShimRat can list directories. |
| T1083 File and Directory Discovery |
MalwareObliqueRAT | ObliqueRAT has the ability to recursively enumerate files on an infected endpoint. |
| T1083 File and Directory Discovery |
MalwareSHOTPUT | SHOTPUT has a command to obtain a directory listing. |
| T1083 File and Directory Discovery |
MalwareAvaddon | Avaddon has searched for specific files prior to encryption. |
| T1083 File and Directory Discovery |
MalwareXAgentOSX | XAgentOSX contains the readFiles function to return a detailed listing (sometimes recursive) of a specified directory. XAgentOSX contains the showBackupIosFolder function to check for IOS device backups by running |
| T1083 File and Directory Discovery |
MalwareChina Chopper | China Chopper's server component can list directory contents. |
| T1083 File and Directory Discovery |
MalwareLightSpy | LightSpy uses the `NSFileManager` to move, create and delete files. LightSpy can also use the assembly `bt` instruction to determine a file's executable permissions. |
| T1083 File and Directory Discovery |
MalwareCheerscrypt | Cheerscrypt can search for log and VMware-related files with .log, .vmdk, .vmem, .vswp, and .vmsn extensions. |
| T1083 File and Directory Discovery |
MalwareKeyBoy | KeyBoy has a command to launch a file browser or explorer on the system. |
| T1083 File and Directory Discovery |
MalwareMiniDuke | MiniDuke can enumerate local drives. |
| T1083 File and Directory Discovery |
MalwarePteranodon | Pteranodon identifies files matching certain file extension and copies them to subdirectories it created. |
| T1083 File and Directory Discovery |
MalwareBeaverTail | BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration. |
| T1083 File and Directory Discovery |
MalwareROKRAT | ROKRAT has the ability to gather a list of files and directories on the infected system. |
| T1083 File and Directory Discovery |
MalwareBabuk | Babuk has the ability to enumerate files on a targeted system. |
| T1083 File and Directory Discovery |
MalwareExbyte | Exbyte enumerates all document files on an infected machine, then creates a summary of these items including filename and directory location prior to exfiltration to cloud hosting services. |
| T1083 File and Directory Discovery |
MalwareDarkWatchman | DarkWatchman has the ability to enumerate file and folder names. |
| T1083 File and Directory Discovery |
MalwareBlackMould | BlackMould has the ability to find files on the targeted system. |
| T1083 File and Directory Discovery |
MalwarePACEMAKER | PACEMAKER can parse `/proc/"process_name"/cmdline` to look for the string `dswsd` within the command line. |
| T1083 File and Directory Discovery |
MalwareBBSRAT | BBSRAT can list file and directory information. |
| T1083 File and Directory Discovery |
MalwarePlugX | PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution. |
| T1083 File and Directory Discovery |
MalwareBisonal | Bisonal can retrieve a file listing from the system. |
| T1083 File and Directory Discovery |
MalwareMultiLayer Wiper | MultiLayer Wiper generates a list of all files and paths on the fixed drives of an infected system, enumerating all files on the system except specific folders defined in a hardcoded list. |
| T1083 File and Directory Discovery |
MalwareDustySky | DustySky scans the victim for files that contain certain keywords and document types including PDF, DOC, DOCX, XLS, and XLSX, from a list that is obtained from the C2 as a text file. It can also identify logical drives for the infected machine. |
| T1083 File and Directory Discovery |
MalwareRemsec | Remsec is capable of listing contents of folders on the victim. Remsec also searches for custom network encryption software on victims. |
| T1083 File and Directory Discovery |
MalwareRover | Rover automatically searches for files on local drives based on a predefined list of file extensions. |
| T1083 File and Directory Discovery |
MalwareEpic | Epic recursively searches for all .doc files on the system and collects a directory listing of the Desktop, %TEMP%, and %WINDOWS%\Temp directories. |
| T1083 File and Directory Discovery |
MalwarePeppy | Peppy can identify specific files for exfiltration. |
| T1083 File and Directory Discovery |
MalwareCuba | Cuba can enumerate files by using a variety of functions. |
| T1083 File and Directory Discovery |
MalwareDEATHRANSOM | DEATHRANSOM can use loop operations to enumerate directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareClambling | Clambling can browse directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareAkira | Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as |
| T1083 File and Directory Discovery |
MalwareDarkGate | Some versions of DarkGate search for the hard-coded folder |
| T1083 File and Directory Discovery |
MalwareLockBit 3.0 | LockBit 3.0 can exclude files associated with core system functions from encryption. |
| T1083 File and Directory Discovery |
MalwareFoggyWeb | FoggyWeb's loader can check for the FoggyWeb backdoor .pri file on a compromised AD FS server. |
| T1083 File and Directory Discovery |
MalwareHydraq | Hydraq creates a backdoor through which remote attackers can check for the existence of files, including its own components, as well as retrieve a list of logical drives. |
| T1083 File and Directory Discovery |
MalwareCreepyDrive | CreepyDrive can specify the local file path to upload files from. |
| T1083 File and Directory Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can search for files in directories. |
| T1083 File and Directory Discovery |
MalwareElise | A variant of Elise executes |
| T1083 File and Directory Discovery |
MalwareUSBferry | USBferry can detect the victim's file or folder list. |
| T1083 File and Directory Discovery |
MalwareWannaCry | WannaCry searches for variety of user files by file extension before encrypting them using RSA and AES, including Office, PDF, image, audio, video, source code, archive/compression format, and key and certificate files. |
| T1083 File and Directory Discovery |
MalwareTSCookie | TSCookie has the ability to discover drive information on the infected host. |
| T1083 File and Directory Discovery |
MalwareLatrodectus | Latrodectus can collect desktop filenames. |
| T1083 File and Directory Discovery |
MalwareSaint Bot | Saint Bot can search a compromised host for specific files. |
| T1083 File and Directory Discovery |
MalwareLODEINFO | LODEINFO has the ability to designate specific files and folders to encryption. |
| T1083 File and Directory Discovery |
MalwareCharmPower | CharmPower can enumerate drives and list the contents of the C: drive on a victim's computer. |
| T1083 File and Directory Discovery |
MalwareTYPEFRAME | TYPEFRAME can search directories for files on the victim’s machine. |
| T1083 File and Directory Discovery |
Malware3PARA RAT | 3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory. |
| T1083 File and Directory Discovery |
MalwareTAINTEDSCRIBE | TAINTEDSCRIBE can use |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.