Real-world descriptions of how a group, tool or campaign used a technique.
4628 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
GroupLuminousMoth | LuminousMoth has used malware that scans for files in the Documents, Desktop, and Download folders and in other drives. |
| T1083 File and Directory Discovery |
GroupAPT28 | APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection. The group also searched a compromised DCCC computer for specific terms. |
| T1083 File and Directory Discovery |
GroupAPT5 | APT5 has used the BLOODMINE utility to discover files with .css, .jpg, .png, .gif, .ico, .js, and .jsp extensions in Pulse Secure Connect logs. |
| T1083 File and Directory Discovery |
GroupFox Kitten | Fox Kitten has used WizTree to obtain network files and directory listings. |
| T1083 File and Directory Discovery |
GroupWinnti Group | Winnti Group has used a program named ff.exe to search for specific documents on compromised hosts. |
| T1083 File and Directory Discovery |
GroupLazarus Group | Lazarus Group malware can use a common function to identify target files by their extension, and some also enumerate files and directories, including a Destover-like variant that lists files and gathers information for all drives. |
| T1083 File and Directory Discovery |
GroupSowbug | Sowbug identified and extracted all Word documents on a server by using a command containing * .doc and *.docx. The actors also searched for documents based on a specific date range and attempted to identify all installed software on a victim. |
| T1083 File and Directory Discovery |
GroupVelvet Ant | Velvet Ant has enumerated local files and folders on victim devices. |
| T1083 File and Directory Discovery |
GroupInception | Inception used a file listing plugin to collect information about file and directories both on local and remote drives. |
| T1083 File and Directory Discovery |
GroupPlay | Play has used the Grixba information stealer to list security files and processes. |
| T1083 File and Directory Discovery |
GroupMagic Hound | Magic Hound malware can list a victim's logical drives and the type, as well the total/free space of the fixed devices. Other malware can list a directory's contents. |
| T1083 File and Directory Discovery |
GroupFIN13 | FIN13 has used the Windows `dir` command to enumerate files and directories in a victim's network. |
| T1083 File and Directory Discovery |
GroupShinyHunters | ShinyHunters has checked mount points for Oracle PeopleSoft configurations and has checked the process scheduler configuration file psappsrv.cfg. Additionally, ShinyHunters has read WebLogic server XML configurations files (config.xml). |
| T1087 Account Discovery |
GroupScattered Spider | Scattered Spider has identified vSphere administrator accounts. |
| T1087 Account Discovery |
GroupAquatic Panda | Aquatic Panda used the |
| T1087 Account Discovery |
GroupFIN13 | FIN13 has enumerated all users and their roles from a victim's main treasury system. |
| T1087.001 Local Account |
GroupAPT3 | APT3 has used a tool that can obtain info about local and global group users, power users, and administrators. |
| T1087.001 Local Account |
Groupadmin@338 | admin@338 actors used the following commands following exploitation of a machine with LOWBALL malware to enumerate user accounts: |
| T1087.001 Local Account |
GroupVolt Typhoon | Volt Typhoon has executed `net user` and `quser` to enumerate local account information. |
| T1087.001 Local Account |
GroupAPT41 | APT41 used built-in |
| T1087.001 Local Account |
GroupAPT32 | APT32 enumerated administrative users using the commands |
| T1087.001 Local Account |
GroupMoses Staff | Moses Staff has collected the administrator username from a compromised host. |
| T1087.001 Local Account |
GroupOilRig | OilRig has run |
| T1087.001 Local Account |
GroupKe3chang | Ke3chang performs account discovery using commands such as |
| T1087.001 Local Account |
GroupAPT1 | APT1 used the commands |
| T1087.001 Local Account |
GroupTurla | Turla has used |
| T1087.001 Local Account |
GroupPoseidon Group | Poseidon Group searches for administrator accounts on both the local victim machine and the network. |
| T1087.001 Local Account |
GroupRedCurl | RedCurl has collected information about local accounts. |
| T1087.001 Local Account |
GroupLotus Blossom | Lotus Blossom has used commands such as `net` to profile local system users. |
| T1087.001 Local Account |
GroupChimera | Chimera has used |
| T1087.001 Local Account |
GroupMedusa Group | Medusa Group has leveraged `net user` for account discovery. |
| T1087.001 Local Account |
GroupAPT42 | APT42 has used the PowerShell-based POWERPOST script to collect local account names from the victim machine. |
| T1087.001 Local Account |
GroupFox Kitten | Fox Kitten has accessed ntuser.dat and UserClass.dat on compromised hosts. |
| T1087.001 Local Account |
GroupThreat Group-3390 | Threat Group-3390 has used |
| T1087.002 Domain Account |
GroupBlackByte | BlackByte has used tools such as AdFind to identify and enumerate domain accounts. |
| T1087.002 Domain Account |
GroupVolt Typhoon | Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery. |
| T1087.002 Domain Account |
GroupAPT41 | APT41 used built-in |
| T1087.002 Domain Account |
GroupDragonfly | Dragonfly has used batch scripts to enumerate users on a victim domain controller. |
| T1087.002 Domain Account |
GroupmenuPass | menuPass has used the Microsoft administration tool csvde.exe to export Active Directory data. |
| T1087.002 Domain Account |
GroupMuddyWater | MuddyWater has used |
| T1087.002 Domain Account |
GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1087.002 Domain Account |
GroupStorm-1811 | Storm-1811 has performed domain account enumeration during intrusions. |
| T1087.002 Domain Account |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information. |
| T1087.002 Domain Account |
GroupSandworm Team | Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about usernames listed in AD. |
| T1087.002 Domain Account |
GroupMustang Panda | Mustang Panda has utilized AdFind to identify domain users. |
| T1087.002 Domain Account |
GroupScattered Spider | Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment. |
| T1087.002 Domain Account |
GroupOilRig | OilRig has run |
| T1087.002 Domain Account |
GroupKe3chang | Ke3chang performs account discovery using commands such as |
| T1087.002 Domain Account |
GroupTurla | Turla has used |
| T1087.002 Domain Account |
GroupStorm-0501 | Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.