Real-world descriptions of how a group, tool or campaign used a technique.
308 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareUSBStealer | USBStealer searches victim drives for files matching certain extensions (“.skr”,“.pkr” or “.key”) or names. |
| T1083 File and Directory Discovery |
MalwareTaidoor | Taidoor can search for specific files. |
| T1083 File and Directory Discovery |
MalwareKivars | Kivars has the ability to list drives on the infected host. |
| T1083 File and Directory Discovery |
MalwareCaddyWiper | CaddyWiper can enumerate all files and directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareCyclops Blink | Cyclops Blink can use the Linux API `statvfs` to enumerate the current working directory. |
| T1083 File and Directory Discovery |
MalwareSeasalt | Seasalt has the capability to identify the drive type on a victim. |
| T1083 File and Directory Discovery |
MalwareTajMahal | TajMahal has the ability to index files from drives, user profiles, and removable drives. |
| T1083 File and Directory Discovery |
MalwarePLEAD | PLEAD has the ability to list drives and files on the compromised host. |
| T1083 File and Directory Discovery |
MalwareRaccoon Stealer | Raccoon Stealer identifies target files and directories for collection based on a configuration file. |
| T1083 File and Directory Discovery |
MalwareCardinal RAT | Cardinal RAT checks its current working directory upon execution and also contains watchdog functionality that ensures its executable is located in the correct path (else it will rewrite the payload). |
| T1083 File and Directory Discovery |
MalwarePisloader | Pisloader has commands to list drives on the victim machine and to list file information for a given directory. |
| T1083 File and Directory Discovery |
MalwareGoldenSpy | GoldenSpy has included a program "ExeProtector", which monitors for the existence of GoldenSpy on the infected system and redownloads if necessary. |
| T1083 File and Directory Discovery |
MalwareGold Dragon | Gold Dragon lists the directories for Desktop, program files, and the user’s recently accessed files. |
| T1083 File and Directory Discovery |
MalwareRamsay | Ramsay can collect directory and file lists. |
| T1083 File and Directory Discovery |
MalwareAshTag | The AshTag AshenOrchestrator component can enumerate files on victim hosts. |
| T1083 File and Directory Discovery |
MalwareMacMa | MacMa can search for a specific file on the compromised computer and can enumerate files in Desktop, Downloads, and Documents folders. |
| T1083 File and Directory Discovery |
MalwareFunnyDream | FunnyDream can identify files with .doc, .docx, .ppt, .pptx, .xls, .xlsx, and .pdf extensions and specific timestamps for collection. |
| T1083 File and Directory Discovery |
MalwareROADSWEEP | ROADSWEEP can enumerate files on infected devices and avoid encrypting files with .exe, .dll, .sys, .lnk, or . lck extensions. |
| T1083 File and Directory Discovery |
MalwareSUNSPOT | SUNSPOT enumerated the Orion software Visual Studio solution directory path. |
| T1083 File and Directory Discovery |
MalwareSysUpdate | SysUpdate can search files on a compromised host. |
| T1083 File and Directory Discovery |
MalwareOutSteel | OutSteel can search for specific file extensions, including zipped files. |
| T1083 File and Directory Discovery |
MalwareBackConfig | BackConfig has the ability to identify folders and files related to previous infections. |
| T1083 File and Directory Discovery |
MalwareANELLDR | ANELLDR can enumerate files in the current directory to search for encrypted payload files. |
| T1083 File and Directory Discovery |
MalwareKwampirs | Kwampirs collects a list of files and directories in C:\ with the command |
| T1083 File and Directory Discovery |
MalwareBoomBox | BoomBox can search for specific files and directories on a machine. |
| T1083 File and Directory Discovery |
MalwareLAMEHUG | LAMEHUG can target directories on victim machines for file collection. |
| T1083 File and Directory Discovery |
MalwareMango | Mango can enumerate the contents of current working or other specified directories. |
| T1083 File and Directory Discovery |
MalwareInnaputRAT | InnaputRAT enumerates directories and obtains file attributes on a system. |
| T1083 File and Directory Discovery |
MalwareGrimAgent | GrimAgent has the ability to enumerate files and directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareLookBack | LookBack can retrieve file listings from the victim machine. |
| T1083 File and Directory Discovery |
MalwareClop | Clop has searched folders and subfolders for files to encrypt. |
| T1083 File and Directory Discovery |
MalwareLokibot | Lokibot can search for specific files on an infected host. |
| T1083 File and Directory Discovery |
MalwarePoetRAT | PoetRAT has the ability to list files upon receiving the |
| T1083 File and Directory Discovery |
MalwareCHOPSTICK | An older version of CHOPSTICK has a module that monitors all mounted volumes for files with the extensions .doc, .docx, .pgp, .gpg, .m2f, or .m2o. |
| T1083 File and Directory Discovery |
MalwareStealBit | StealBit can be configured to exfiltrate specific file types. |
| T1083 File and Directory Discovery |
MalwareZxShell | ZxShell has a command to open a file manager and explorer on the system. |
| T1083 File and Directory Discovery |
MalwareNDiskMonitor | NDiskMonitor can obtain a list of all files and directories as well as logical drives. |
| T1083 File and Directory Discovery |
MalwareDDKONG | DDKONG lists files on the victim’s machine. |
| T1083 File and Directory Discovery |
MalwarePenquin | Penquin can use the command code |
| T1083 File and Directory Discovery |
MalwareBabyShark | BabyShark has used |
| T1083 File and Directory Discovery |
MalwareCannon | Cannon can obtain victim drive information as well as a list of folders in C:\Program Files. |
| T1083 File and Directory Discovery |
MalwareWinnti for Windows | Winnti for Windows can check for the presence of specific files prior to moving to the next phase of execution. |
| T1083 File and Directory Discovery |
MalwareTroll Stealer | Troll Stealer can enumerate and collect items from local drives and folders. |
| T1083 File and Directory Discovery |
MalwareBLACKCOFFEE | BLACKCOFFEE has the capability to enumerate files. |
| T1083 File and Directory Discovery |
MalwareKinsing | Kinsing has used the find command to search for specific files. |
| T1083 File and Directory Discovery |
MalwarenjRAT | njRAT can browse file systems using a file manager module. |
| T1083 File and Directory Discovery |
MalwareZIPLINE | ZIPLINE can find and append specific files on Ivanti Connect Secure VPNs based upon received commands. |
| T1083 File and Directory Discovery |
MalwareChChes | ChChes collects the victim's %TEMP% directory path and version of Internet Explorer. |
| T1083 File and Directory Discovery |
MalwareManjusaka | Manjusaka can gather information about specific files on the victim system. |
| T1083 File and Directory Discovery |
MalwareIceApple | The IceApple Directory Lister module can list information about files and directories including creation time, last write time, name, and size. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.