ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1083×

308 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
MalwareJPIN

JPIN can enumerate drives and their types. It can also change file permissions using cacls.exe.

T1083
File and Directory Discovery
MalwaremetaMain

metaMain can recursively enumerate files in an operator-provided directory.

T1083
File and Directory Discovery
MalwareSideTwist

SideTwist has the ability to search for specific files.

T1083
File and Directory Discovery
MalwarePsylo

Psylo has commands to enumerate all storage devices and to find all files that start with a particular string.

T1083
File and Directory Discovery
MalwareHeyoka Backdoor

Heyoka Backdoor has the ability to search the compromised host for files.

T1083
File and Directory Discovery
MalwareHTTPBrowser

HTTPBrowser is capable of listing files, folders, and drives on a victim.

T1083
File and Directory Discovery
MalwareLunarWeb

LunarWeb has the ability to retrieve directory listings.

T1083
File and Directory Discovery
MalwareXCSSET

XCSSET has used `mdfind` to enumerate a list of apps known to grant screen sharing permissions and leverages a module to run the command `ls -la ~/Desktop`.

T1083
File and Directory Discovery
MalwareOctopus

Octopus can collect information on the Windows directory and searches for compressed RAR files on the host.

T1083
File and Directory Discovery
MalwareKillDisk

KillDisk has used the FindNextFile command as part of its file deletion process.

T1083
File and Directory Discovery
MalwareQilin

Qilin can exclude specific directories and files from encryption.

T1083
File and Directory Discovery
MalwareSoreFang

SoreFang has the ability to list directories.

T1083
File and Directory Discovery
MalwareIndustroyer

Industroyer’s data wiper component enumerates specific files on all the Windows drives.

T1083
File and Directory Discovery
MalwareLazyWiper

LazyWiper can specifically target multiple files by extension including: .rar, .tar.gz, .zip, .7z, .json, .bcp, .bak, .gho, .erf, .edb, .onepkg, .pst, and .ldiff.

T1083
File and Directory Discovery
MalwarePcexter

Pcexter has the ability to search for files in specified directories.

T1083
File and Directory Discovery
MalwarePasam

Pasam creates a backdoor through which remote attackers can retrieve lists of files.

T1083
File and Directory Discovery
MalwareBADNEWS

BADNEWS identifies files with certain extensions from USB devices, then copies them to a predefined directory.

T1083
File and Directory Discovery
MalwareLinfo

Linfo creates a backdoor through which remote attackers can list contents of drives and search for files.

T1083
File and Directory Discovery
MalwareRemexi

Remexi searches for files on the system.

T1083
File and Directory Discovery
MalwareQakBot

QakBot can identify whether it has been run previously on a host by checking for a specified folder.

T1083
File and Directory Discovery
MalwareCookieMiner

CookieMiner has looked for files in the user's home directory with "wallet" in their name using find.

T1083
File and Directory Discovery
MalwareGelsemium

Gelsemium can retrieve data from specific Windows directories, as well as open random files as part of Virtualization/Sandbox Evasion.

T1083
File and Directory Discovery
MalwarejRAT

jRAT can browse file systems.

T1083
File and Directory Discovery
MalwareOSX/Shlayer

OSX/Shlayer has used the command appDir="$(dirname $(dirname "$currentDir"))" and $(dirname "$(pwd -P)") to construct installation paths.

T1083
File and Directory Discovery
MalwareDenis

Denis has several commands to search directories for files.

T1083
File and Directory Discovery
MalwareINC Ransomware

INC Ransomware can receive command line arguments to encrypt specific files and directories.

T1083
File and Directory Discovery
MalwareSplatCloak

SplatCloak has used Windows API to identify files associated with Windows Defender and Kaspersky.

T1083
File and Directory Discovery
MalwareFIVEHANDS

FIVEHANDS has the ability to enumerate files on a compromised host in order to encrypt files with specific extensions.

T1083
File and Directory Discovery
MalwareAutoIt backdoor

AutoIt backdoor is capable of identifying documents on the victim with the following extensions: .doc; .pdf, .csv, .ppt, .docx, .pst, .xls, .xlsx, .pptx, and .jpeg.

T1083
File and Directory Discovery
MalwareDtrack

Dtrack can list files on available disk volumes.

T1083
File and Directory Discovery
MalwareAzorult

Azorult can recursively search for files in folders and collects files from the desktop with certain extensions.

T1083
File and Directory Discovery
MalwareBACKSPACE

BACKSPACE allows adversaries to search for files.

T1083
File and Directory Discovery
MalwareZox

Zox can enumerate files on a compromised host.

T1083
File and Directory Discovery
MalwareUPPERCUT

UPPERCUT has the capability to gather the victim's current directory.

T1083
File and Directory Discovery
MalwareADVSTORESHELL

ADVSTORESHELL can list files and directories.

T1083
File and Directory Discovery
MalwareStrifeWater

StrifeWater can enumerate files on a compromised host.

T1083
File and Directory Discovery
MalwareWarzoneRAT

WarzoneRAT can enumerate directories on a compromise host.

T1083
File and Directory Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA can enumerate files and directories.

T1083
File and Directory Discovery
MalwareFALLCHILL

FALLCHILL can search files on a victim.

T1083
File and Directory Discovery
ToolRemoteUtilities

RemoteUtilities can enumerate files and directories on a target machine.

T1083
File and Directory Discovery
ToolDiskpart

If executed with elevated privileges, Diskpart can list all volumes, including virtual disks.

T1083
File and Directory Discovery
ToolSliver

Sliver can enumerate files on a target system.

T1083
File and Directory Discovery
ToolSILENTTRINITY

SILENTTRINITY has several modules, such as `ls.py`, `pwd.py`, and `recentFiles.py`, to enumerate directories and files.

T1083
File and Directory Discovery
ToolEmpire

Empire includes various modules for finding files of interest on hosts and network shares.

T1083
File and Directory Discovery
ToolPoshC2

PoshC2 can enumerate files on the local file system and includes a module for enumerating recently accessed files.

T1083
File and Directory Discovery
ToolRclone

Rclone can list files and directories with the `ls`, `lsd`, and `lsl` commands.

T1083
File and Directory Discovery
ToolTruffleHog

TruffleHog has can browse and scan individual files and directories.

T1083
File and Directory Discovery
ToolRemcos

Remcos can search for files on the infected machine.

T1083
File and Directory Discovery
ToolImminent Monitor

Imminent Monitor has a dynamic debugging feature to check whether it is located in the %TEMP% directory, otherwise it copies itself there.

T1083
File and Directory Discovery
ToolForfiles

Forfiles can be used to locate certain types of files/directories in a system.(ex: locate all files with a specific extension, name, and/or age)

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.