ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1083×

308 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
MalwareRising Sun

Rising Sun can enumerate information about files from the infected system, including file size, attributes, creation time, last access time, and write time. Rising Sun can enumerate the compilation timestamp of Windows executable files.

T1083
File and Directory Discovery
MalwareNotPetya

NotPetya searches for files ending with dozens of different file extensions prior to encryption.

T1083
File and Directory Discovery
MalwareShimRat

ShimRat can list directories.

T1083
File and Directory Discovery
MalwareObliqueRAT

ObliqueRAT has the ability to recursively enumerate files on an infected endpoint.

T1083
File and Directory Discovery
MalwareSHOTPUT

SHOTPUT has a command to obtain a directory listing.

T1083
File and Directory Discovery
MalwareAvaddon

Avaddon has searched for specific files prior to encryption.

T1083
File and Directory Discovery
MalwareXAgentOSX

XAgentOSX contains the readFiles function to return a detailed listing (sometimes recursive) of a specified directory. XAgentOSX contains the showBackupIosFolder function to check for IOS device backups by running ls -la ~/Library/Application\ Support/MobileSync/Backup/.

T1083
File and Directory Discovery
MalwareChina Chopper

China Chopper's server component can list directory contents.

T1083
File and Directory Discovery
MalwareLightSpy

LightSpy uses the `NSFileManager` to move, create and delete files. LightSpy can also use the assembly `bt` instruction to determine a file's executable permissions.

T1083
File and Directory Discovery
MalwareCheerscrypt

Cheerscrypt can search for log and VMware-related files with .log, .vmdk, .vmem, .vswp, and .vmsn extensions.

T1083
File and Directory Discovery
MalwareKeyBoy

KeyBoy has a command to launch a file browser or explorer on the system.

T1083
File and Directory Discovery
MalwareMiniDuke

MiniDuke can enumerate local drives.

T1083
File and Directory Discovery
MalwarePteranodon

Pteranodon identifies files matching certain file extension and copies them to subdirectories it created.

T1083
File and Directory Discovery
MalwareBeaverTail

BeaverTail has searched for .ldb and .log files stored in browser extension directories for collection and exfiltration.

T1083
File and Directory Discovery
MalwareROKRAT

ROKRAT has the ability to gather a list of files and directories on the infected system.

T1083
File and Directory Discovery
MalwareBabuk

Babuk has the ability to enumerate files on a targeted system.

T1083
File and Directory Discovery
MalwareExbyte

Exbyte enumerates all document files on an infected machine, then creates a summary of these items including filename and directory location prior to exfiltration to cloud hosting services.

T1083
File and Directory Discovery
MalwareDarkWatchman

DarkWatchman has the ability to enumerate file and folder names.

T1083
File and Directory Discovery
MalwareBlackMould

BlackMould has the ability to find files on the targeted system.

T1083
File and Directory Discovery
MalwarePACEMAKER

PACEMAKER can parse `/proc/"process_name"/cmdline` to look for the string `dswsd` within the command line.

T1083
File and Directory Discovery
MalwareBBSRAT

BBSRAT can list file and directory information.

T1083
File and Directory Discovery
MalwarePlugX

PlugX has a module to enumerate drives and find files recursively. PlugX has also checked the path from which it is running for specific parameters prior to execution.

T1083
File and Directory Discovery
MalwareBisonal

Bisonal can retrieve a file listing from the system.

T1083
File and Directory Discovery
MalwareMultiLayer Wiper

MultiLayer Wiper generates a list of all files and paths on the fixed drives of an infected system, enumerating all files on the system except specific folders defined in a hardcoded list.

T1083
File and Directory Discovery
MalwareDustySky

DustySky scans the victim for files that contain certain keywords and document types including PDF, DOC, DOCX, XLS, and XLSX, from a list that is obtained from the C2 as a text file. It can also identify logical drives for the infected machine.

T1083
File and Directory Discovery
MalwareRemsec

Remsec is capable of listing contents of folders on the victim. Remsec also searches for custom network encryption software on victims.

T1083
File and Directory Discovery
MalwareRover

Rover automatically searches for files on local drives based on a predefined list of file extensions.

T1083
File and Directory Discovery
MalwareEpic

Epic recursively searches for all .doc files on the system and collects a directory listing of the Desktop, %TEMP%, and %WINDOWS%\Temp directories.

T1083
File and Directory Discovery
MalwarePeppy

Peppy can identify specific files for exfiltration.

T1083
File and Directory Discovery
MalwareCuba

Cuba can enumerate files by using a variety of functions.

T1083
File and Directory Discovery
MalwareDEATHRANSOM

DEATHRANSOM can use loop operations to enumerate directories on a compromised host.

T1083
File and Directory Discovery
MalwareClambling

Clambling can browse directories on a compromised host.

T1083
File and Directory Discovery
MalwareAkira

Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as GetFileAttributesW.

T1083
File and Directory Discovery
MalwareDarkGate

Some versions of DarkGate search for the hard-coded folder C:\Program Files\e Carte Bleue.

T1083
File and Directory Discovery
MalwareLockBit 3.0

LockBit 3.0 can exclude files associated with core system functions from encryption.

T1083
File and Directory Discovery
MalwareFoggyWeb

FoggyWeb's loader can check for the FoggyWeb backdoor .pri file on a compromised AD FS server.

T1083
File and Directory Discovery
MalwareHydraq

Hydraq creates a backdoor through which remote attackers can check for the existence of files, including its own components, as well as retrieve a list of logical drives.

T1083
File and Directory Discovery
MalwareCreepyDrive

CreepyDrive can specify the local file path to upload files from.

T1083
File and Directory Discovery
MalwareCaterpillar WebShell

Caterpillar WebShell can search for files in directories.

T1083
File and Directory Discovery
MalwareElise

A variant of Elise executes dir C:\progra~1 when initially run.

T1083
File and Directory Discovery
MalwareUSBferry

USBferry can detect the victim's file or folder list.

T1083
File and Directory Discovery
MalwareWannaCry

WannaCry searches for variety of user files by file extension before encrypting them using RSA and AES, including Office, PDF, image, audio, video, source code, archive/compression format, and key and certificate files.

T1083
File and Directory Discovery
MalwareTSCookie

TSCookie has the ability to discover drive information on the infected host.

T1083
File and Directory Discovery
MalwareLatrodectus

Latrodectus can collect desktop filenames.

T1083
File and Directory Discovery
MalwareSaint Bot

Saint Bot can search a compromised host for specific files.

T1083
File and Directory Discovery
MalwareLODEINFO

LODEINFO has the ability to designate specific files and folders to encryption.

T1083
File and Directory Discovery
MalwareCharmPower

CharmPower can enumerate drives and list the contents of the C: drive on a victim's computer.

T1083
File and Directory Discovery
MalwareTYPEFRAME

TYPEFRAME can search directories for files on the victim’s machine.

T1083
File and Directory Discovery
Malware3PARA RAT

3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory.

T1083
File and Directory Discovery
MalwareTAINTEDSCRIBE

TAINTEDSCRIBE can use DirectoryList to enumerate files in a specified directory.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.