Real-world descriptions of how a group, tool or campaign used a technique.
308 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareRoyal | Royal can identify specific files and directories to exclude from the encryption process. |
| T1083 File and Directory Discovery |
MalwareUroburos | Uroburos can search for specific files on a compromised system. |
| T1083 File and Directory Discovery |
MalwareMetamorfo | Metamorfo has searched the Program Files directories for specific folders and has searched for strings related to its mutexes. |
| T1083 File and Directory Discovery |
MalwareSpica | Spica can list filesystem contents on targeted systems. |
| T1083 File and Directory Discovery |
MalwareEmbargo | Embargo has searched for folders, subfolders and other networked or mounted drives for follow on encryption actions. Embargo has also iterated device volumes using `FindFirstVolumeW()` and `FindNextVolumeW()` functions and then calls the `GetVolumePathNamesForVolumeNameW()` function to retrieve a list of drive letters and mounted folder paths for each specified volume. |
| T1083 File and Directory Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can enumerate files and directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareBandook | Bandook has a command to list files on a system. |
| T1083 File and Directory Discovery |
MalwareTINYTYPHON | TINYTYPHON searches through the drive containing the OS, then all drive letters C through to Z, for documents matching certain extensions. |
| T1083 File and Directory Discovery |
MalwareKONNI | A version of KONNI searches for filenames created with a previous version of the malware, suggesting different versions targeted the same victims and the versions may work together. |
| T1083 File and Directory Discovery |
MalwareCORALDECK | CORALDECK searches for specified files. |
| T1083 File and Directory Discovery |
MalwareSPACESHIP | SPACESHIP identifies files and directories for collection by searching for specific file extensions or file modification time. |
| T1083 File and Directory Discovery |
MalwareBLUELIGHT | BLUELIGHT can enumerate files and collect associated metadata. |
| T1083 File and Directory Discovery |
MalwareKGH_SPY | KGH_SPY can enumerate files and directories on a compromised host. |
| T1083 File and Directory Discovery |
Malwaredown_new | down_new has the ability to list the directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareIxeshe | Ixeshe can list file and directory information. |
| T1083 File and Directory Discovery |
MalwareMicropsia | Micropsia can perform a recursive directory listing for all volume drives available on the victim's machine and can also fetch specific files by their paths. |
| T1083 File and Directory Discovery |
MalwareRARSTONE | RARSTONE obtains installer properties from Uninstall Registry Key entries to obtain information about installed applications and how to uninstall certain applications. |
| T1083 File and Directory Discovery |
MalwareBlack Basta | Black Basta can enumerate specific files for encryption. |
| T1083 File and Directory Discovery |
Malware4H RAT | 4H RAT has the capability to obtain file and directory listings. |
| T1083 File and Directory Discovery |
MalwareAttor | Attor has a plugin that enumerates files with specific extensions on all hard disk drives and stores file information in encrypted log files. |
| T1083 File and Directory Discovery |
MalwareMegaCortex | MegaCortex can parse the available drives and directories to determine which files to encrypt. |
| T1083 File and Directory Discovery |
MalwareStreamEx | StreamEx has the ability to enumerate drive types. |
| T1083 File and Directory Discovery |
MalwareBoxCaon | BoxCaon has searched for files on the system, such as documents located in the desktop folder. |
| T1083 File and Directory Discovery |
MalwareNightClub | NightClub can use a file monitor to identify .lnk, .doc, .docx, .xls, .xslx, and .pdf files. |
| T1083 File and Directory Discovery |
MalwareAkira _v2 | Akira _v2 can target specific files and folders for encryption. |
| T1083 File and Directory Discovery |
MalwareSDBbot | SDBbot has the ability to get directory listings or drive information on a compromised host. |
| T1083 File and Directory Discovery |
MalwareRTM | RTM can check for specific files and directories associated with virtualization and malware analysis. |
| T1083 File and Directory Discovery |
MalwareDerusbi | Derusbi is capable of obtaining directory, file, and drive listings. |
| T1083 File and Directory Discovery |
MalwareBazar | Bazar can enumerate the victim's desktop. |
| T1083 File and Directory Discovery |
MalwareBadPatch | BadPatch searches for files with specific file extensions. |
| T1083 File and Directory Discovery |
MalwareMESSAGETAP | MESSAGETAP checks for the existence of two configuration files (keyword_parm.txt and parm.txt) and attempts to read the files every 30 seconds. |
| T1083 File and Directory Discovery |
MalwareSUGARDUMP | SUGARDUMP can search for and collect data from specific Chrome, Opera, Microsoft Edge, and Firefox files, including any folders that have the string `Profile` in its name. |
| T1083 File and Directory Discovery |
MalwareSOUNDBITE | SOUNDBITE is capable of enumerating and manipulating files and directories. |
| T1083 File and Directory Discovery |
MalwareMoonWind | MoonWind has a command to return a directory listing for a specified directory. |
| T1083 File and Directory Discovery |
MalwareRyuk | Ryuk has enumerated files and folders on all mounted drives. |
| T1083 File and Directory Discovery |
MalwareCryptoistic | Cryptoistic can scan a directory to identify files for deletion. |
| T1083 File and Directory Discovery |
MalwareHermeticWiper | HermeticWiper can enumerate common folders such as My Documents, Desktop, and AppData. |
| T1083 File and Directory Discovery |
Malwareccf32 | ccf32 can parse collected files to identify specific file extensions. |
| T1083 File and Directory Discovery |
MalwareLockBit 2.0 | LockBit 2.0 can exclude files associated with core system functions from encryption. |
| T1083 File and Directory Discovery |
MalwareZebrocy | Zebrocy searches for files that are 60mb and less and contain the following extensions: .doc, .docx, .xls, .xlsx, .ppt, .pptx, .exe, .zip, and .rar. Zebrocy also runs the |
| T1083 File and Directory Discovery |
MalwareFinFisher | FinFisher enumerates directories and scans for certain files. |
| T1083 File and Directory Discovery |
MalwareLunarMail | LunarMail can search its staging directory for output files it has produced. |
| T1083 File and Directory Discovery |
MalwareCrossRAT | CrossRAT can list all files on a system. |
| T1083 File and Directory Discovery |
MalwareOwaAuth | OwaAuth has a command to list its directory and logical drives. |
| T1083 File and Directory Discovery |
MalwareCobalt Strike | Cobalt Strike can explore files on a compromised system. |
| T1083 File and Directory Discovery |
MalwareSUNBURST | SUNBURST had commands to enumerate files and directories. |
| T1083 File and Directory Discovery |
MalwareHotCroissant | HotCroissant has the ability to retrieve a list of files in a given directory as well as drives and drive types. |
| T1083 File and Directory Discovery |
MalwareREvil | REvil has the ability to identify specific files and directories that are not to be encrypted. |
| T1083 File and Directory Discovery |
MalwareSamurai | Samurai can use a specific module for file enumeration. |
| T1083 File and Directory Discovery |
MalwarePinchDuke | PinchDuke searches for files created within a certain timeframe and whose file extension matches a predefined list. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.