Real-world descriptions of how a group, tool or campaign used a technique.
308 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareJPIN | JPIN can enumerate drives and their types. It can also change file permissions using cacls.exe. |
| T1083 File and Directory Discovery |
MalwaremetaMain | metaMain can recursively enumerate files in an operator-provided directory. |
| T1083 File and Directory Discovery |
MalwareSideTwist | SideTwist has the ability to search for specific files. |
| T1083 File and Directory Discovery |
MalwarePsylo | Psylo has commands to enumerate all storage devices and to find all files that start with a particular string. |
| T1083 File and Directory Discovery |
MalwareHeyoka Backdoor | Heyoka Backdoor has the ability to search the compromised host for files. |
| T1083 File and Directory Discovery |
MalwareHTTPBrowser | HTTPBrowser is capable of listing files, folders, and drives on a victim. |
| T1083 File and Directory Discovery |
MalwareLunarWeb | LunarWeb has the ability to retrieve directory listings. |
| T1083 File and Directory Discovery |
MalwareXCSSET | XCSSET has used `mdfind` to enumerate a list of apps known to grant screen sharing permissions and leverages a module to run the command `ls -la ~/Desktop`. |
| T1083 File and Directory Discovery |
MalwareOctopus | Octopus can collect information on the Windows directory and searches for compressed RAR files on the host. |
| T1083 File and Directory Discovery |
MalwareKillDisk | KillDisk has used the |
| T1083 File and Directory Discovery |
MalwareQilin | Qilin can exclude specific directories and files from encryption. |
| T1083 File and Directory Discovery |
MalwareSoreFang | SoreFang has the ability to list directories. |
| T1083 File and Directory Discovery |
MalwareIndustroyer | Industroyer’s data wiper component enumerates specific files on all the Windows drives. |
| T1083 File and Directory Discovery |
MalwareLazyWiper | LazyWiper can specifically target multiple files by extension including: .rar, .tar.gz, .zip, .7z, .json, .bcp, .bak, .gho, .erf, .edb, .onepkg, .pst, and .ldiff. |
| T1083 File and Directory Discovery |
MalwarePcexter | Pcexter has the ability to search for files in specified directories. |
| T1083 File and Directory Discovery |
MalwarePasam | Pasam creates a backdoor through which remote attackers can retrieve lists of files. |
| T1083 File and Directory Discovery |
MalwareBADNEWS | BADNEWS identifies files with certain extensions from USB devices, then copies them to a predefined directory. |
| T1083 File and Directory Discovery |
MalwareLinfo | Linfo creates a backdoor through which remote attackers can list contents of drives and search for files. |
| T1083 File and Directory Discovery |
MalwareRemexi | Remexi searches for files on the system. |
| T1083 File and Directory Discovery |
MalwareQakBot | QakBot can identify whether it has been run previously on a host by checking for a specified folder. |
| T1083 File and Directory Discovery |
MalwareCookieMiner | CookieMiner has looked for files in the user's home directory with "wallet" in their name using |
| T1083 File and Directory Discovery |
MalwareGelsemium | Gelsemium can retrieve data from specific Windows directories, as well as open random files as part of Virtualization/Sandbox Evasion. |
| T1083 File and Directory Discovery |
MalwarejRAT | jRAT can browse file systems. |
| T1083 File and Directory Discovery |
MalwareOSX/Shlayer | OSX/Shlayer has used the command |
| T1083 File and Directory Discovery |
MalwareDenis | Denis has several commands to search directories for files. |
| T1083 File and Directory Discovery |
MalwareINC Ransomware | INC Ransomware can receive command line arguments to encrypt specific files and directories. |
| T1083 File and Directory Discovery |
MalwareSplatCloak | SplatCloak has used Windows API to identify files associated with Windows Defender and Kaspersky. |
| T1083 File and Directory Discovery |
MalwareFIVEHANDS | FIVEHANDS has the ability to enumerate files on a compromised host in order to encrypt files with specific extensions. |
| T1083 File and Directory Discovery |
MalwareAutoIt backdoor | AutoIt backdoor is capable of identifying documents on the victim with the following extensions: .doc; .pdf, .csv, .ppt, .docx, .pst, .xls, .xlsx, .pptx, and .jpeg. |
| T1083 File and Directory Discovery |
MalwareDtrack | Dtrack can list files on available disk volumes. |
| T1083 File and Directory Discovery |
MalwareAzorult | Azorult can recursively search for files in folders and collects files from the desktop with certain extensions. |
| T1083 File and Directory Discovery |
MalwareBACKSPACE | BACKSPACE allows adversaries to search for files. |
| T1083 File and Directory Discovery |
MalwareZox | Zox can enumerate files on a compromised host. |
| T1083 File and Directory Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to gather the victim's current directory. |
| T1083 File and Directory Discovery |
MalwareADVSTORESHELL | ADVSTORESHELL can list files and directories. |
| T1083 File and Directory Discovery |
MalwareStrifeWater | StrifeWater can enumerate files on a compromised host. |
| T1083 File and Directory Discovery |
MalwareWarzoneRAT | WarzoneRAT can enumerate directories on a compromise host. |
| T1083 File and Directory Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA can enumerate files and directories. |
| T1083 File and Directory Discovery |
MalwareFALLCHILL | FALLCHILL can search files on a victim. |
| T1083 File and Directory Discovery |
ToolRemoteUtilities | RemoteUtilities can enumerate files and directories on a target machine. |
| T1083 File and Directory Discovery |
ToolDiskpart | If executed with elevated privileges, Diskpart can list all volumes, including virtual disks. |
| T1083 File and Directory Discovery |
ToolSliver | Sliver can enumerate files on a target system. |
| T1083 File and Directory Discovery |
ToolSILENTTRINITY | SILENTTRINITY has several modules, such as `ls.py`, `pwd.py`, and `recentFiles.py`, to enumerate directories and files. |
| T1083 File and Directory Discovery |
ToolEmpire | Empire includes various modules for finding files of interest on hosts and network shares. |
| T1083 File and Directory Discovery |
ToolPoshC2 | PoshC2 can enumerate files on the local file system and includes a module for enumerating recently accessed files. |
| T1083 File and Directory Discovery |
ToolRclone | Rclone can list files and directories with the `ls`, `lsd`, and `lsl` commands. |
| T1083 File and Directory Discovery |
ToolTruffleHog | TruffleHog has can browse and scan individual files and directories. |
| T1083 File and Directory Discovery |
ToolRemcos | Remcos can search for files on the infected machine. |
| T1083 File and Directory Discovery |
ToolImminent Monitor | Imminent Monitor has a dynamic debugging feature to check whether it is located in the %TEMP% directory, otherwise it copies itself there. |
| T1083 File and Directory Discovery |
ToolForfiles | Forfiles can be used to locate certain types of files/directories in a system.(ex: locate all files with a specific extension, name, and/or age) |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.