Real-world descriptions of how a group, tool or campaign used a technique.
308 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
Toolcmd | cmd can be used to find files and directories with native functionality such as |
| T1083 File and Directory Discovery |
ToolCrackMapExec | CrackMapExec can discover specified filetypes and log files on a targeted system. |
| T1083 File and Directory Discovery |
ToolKoadic | Koadic can obtain a list of directories. |
| T1083 File and Directory Discovery |
ToolPupy | Pupy can walk through directories and recursively search for strings in files. |
| T1083 File and Directory Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can identify files containing environment variables, SSH keys, cloud credentials, access tokens, and cryptocurrency wallets. |
| T1083 File and Directory Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has enumerated home directories, file paths and files associated with storing or containing credentials and other secrets. |
| T1083 File and Directory Discovery |
MalwareCanisterWorm | CanisterWorm has discovered npm pathways and directories that frequently store .npmrc files to check for _authToken values. |
| T1083 File and Directory Discovery |
MalwareBADFLICK | BADFLICK has searched for files on the infected host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.