ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1083×

308 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
MalwareUSBStealer

USBStealer searches victim drives for files matching certain extensions (“.skr”,“.pkr” or “.key”) or names.

T1083
File and Directory Discovery
MalwareTaidoor

Taidoor can search for specific files.

T1083
File and Directory Discovery
MalwareKivars

Kivars has the ability to list drives on the infected host.

T1083
File and Directory Discovery
MalwareCaddyWiper

CaddyWiper can enumerate all files and directories on a compromised host.

T1083
File and Directory Discovery
MalwareCyclops Blink

Cyclops Blink can use the Linux API `statvfs` to enumerate the current working directory.

T1083
File and Directory Discovery
MalwareSeasalt

Seasalt has the capability to identify the drive type on a victim.

T1083
File and Directory Discovery
MalwareTajMahal

TajMahal has the ability to index files from drives, user profiles, and removable drives.

T1083
File and Directory Discovery
MalwarePLEAD

PLEAD has the ability to list drives and files on the compromised host.

T1083
File and Directory Discovery
MalwareRaccoon Stealer

Raccoon Stealer identifies target files and directories for collection based on a configuration file.

T1083
File and Directory Discovery
MalwareCardinal RAT

Cardinal RAT checks its current working directory upon execution and also contains watchdog functionality that ensures its executable is located in the correct path (else it will rewrite the payload).

T1083
File and Directory Discovery
MalwarePisloader

Pisloader has commands to list drives on the victim machine and to list file information for a given directory.

T1083
File and Directory Discovery
MalwareGoldenSpy

GoldenSpy has included a program "ExeProtector", which monitors for the existence of GoldenSpy on the infected system and redownloads if necessary.

T1083
File and Directory Discovery
MalwareGold Dragon

Gold Dragon lists the directories for Desktop, program files, and the user’s recently accessed files.

T1083
File and Directory Discovery
MalwareRamsay

Ramsay can collect directory and file lists.

T1083
File and Directory Discovery
MalwareAshTag

The AshTag AshenOrchestrator component can enumerate files on victim hosts.

T1083
File and Directory Discovery
MalwareMacMa

MacMa can search for a specific file on the compromised computer and can enumerate files in Desktop, Downloads, and Documents folders.

T1083
File and Directory Discovery
MalwareFunnyDream

FunnyDream can identify files with .doc, .docx, .ppt, .pptx, .xls, .xlsx, and .pdf extensions and specific timestamps for collection.

T1083
File and Directory Discovery
MalwareROADSWEEP

ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions.

T1083
File and Directory Discovery
MalwareSUNSPOT

SUNSPOT enumerated the Orion software Visual Studio solution directory path.

T1083
File and Directory Discovery
MalwareSysUpdate

SysUpdate can search files on a compromised host.

T1083
File and Directory Discovery
MalwareOutSteel

OutSteel can search for specific file extensions, including zipped files.

T1083
File and Directory Discovery
MalwareBackConfig

BackConfig has the ability to identify folders and files related to previous infections.

T1083
File and Directory Discovery
MalwareANELLDR

ANELLDR can enumerate files in the current directory to search for encrypted payload files.

T1083
File and Directory Discovery
MalwareKwampirs

Kwampirs collects a list of files and directories in C:\ with the command dir /s /a c:\ >> "C:\windows\TEMP\[RANDOM].tmp".

T1083
File and Directory Discovery
MalwareBoomBox

BoomBox can search for specific files and directories on a machine.

T1083
File and Directory Discovery
MalwareLAMEHUG

LAMEHUG can target directories on victim machines for file collection.

T1083
File and Directory Discovery
MalwareMango

Mango can enumerate the contents of current working or other specified directories.

T1083
File and Directory Discovery
MalwareInnaputRAT

InnaputRAT enumerates directories and obtains file attributes on a system.

T1083
File and Directory Discovery
MalwareGrimAgent

GrimAgent has the ability to enumerate files and directories on a compromised host.

T1083
File and Directory Discovery
MalwareLookBack

LookBack can retrieve file listings from the victim machine.

T1083
File and Directory Discovery
MalwareClop

Clop has searched folders and subfolders for files to encrypt.

T1083
File and Directory Discovery
MalwareLokibot

Lokibot can search for specific files on an infected host.

T1083
File and Directory Discovery
MalwarePoetRAT

PoetRAT has the ability to list files upon receiving the ls command from C2.

T1083
File and Directory Discovery
MalwareCHOPSTICK

An older version of CHOPSTICK has a module that monitors all mounted volumes for files with the extensions .doc, .docx, .pgp, .gpg, .m2f, or .m2o.

T1083
File and Directory Discovery
MalwareStealBit

StealBit can be configured to exfiltrate specific file types.

T1083
File and Directory Discovery
MalwareZxShell

ZxShell has a command to open a file manager and explorer on the system.

T1083
File and Directory Discovery
MalwareNDiskMonitor

NDiskMonitor can obtain a list of all files and directories as well as logical drives.

T1083
File and Directory Discovery
MalwareDDKONG

DDKONG lists files on the victim’s machine.

T1083
File and Directory Discovery
MalwarePenquin

Penquin can use the command code do_vslist to send file names, size, and status to C2.

T1083
File and Directory Discovery
MalwareBabyShark

BabyShark has used dir to search for "programfiles" and "appdata".

T1083
File and Directory Discovery
MalwareCannon

Cannon can obtain victim drive information as well as a list of folders in C:\Program Files.

T1083
File and Directory Discovery
MalwareWinnti for Windows

Winnti for Windows can check for the presence of specific files prior to moving to the next phase of execution.

T1083
File and Directory Discovery
MalwareTroll Stealer

Troll Stealer can enumerate and collect items from local drives and folders.

T1083
File and Directory Discovery
MalwareBLACKCOFFEE

BLACKCOFFEE has the capability to enumerate files.

T1083
File and Directory Discovery
MalwareKinsing

Kinsing has used the find command to search for specific files.

T1083
File and Directory Discovery
MalwarenjRAT

njRAT can browse file systems using a file manager module.

T1083
File and Directory Discovery
MalwareZIPLINE

ZIPLINE can find and append specific files on Ivanti Connect Secure VPNs based upon received commands.

T1083
File and Directory Discovery
MalwareChChes

ChChes collects the victim's %TEMP% directory path and version of Internet Explorer.

T1083
File and Directory Discovery
MalwareManjusaka

Manjusaka can gather information about specific files on the victim system.

T1083
File and Directory Discovery
MalwareIceApple

The IceApple Directory Lister module can list information about files and directories including creation time, last write time, name, and size.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.