Real-world descriptions of how a group, tool or campaign used a technique.
13 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters. |
| T1083 File and Directory Discovery |
CampaignKV Botnet Activity | KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: |
| T1083 File and Directory Discovery |
CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors leveraged commands to locate accessible file shares, backup paths, or SharePoint content. |
| T1083 File and Directory Discovery |
CampaignOperation Honeybee | During Operation Honeybee, the threat actors used a malicious DLL to search for files with specific keywords. |
| T1083 File and Directory Discovery |
CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to identify sensitive data within the victim environment for extraction. |
| T1083 File and Directory Discovery |
CampaignC0015 | During C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful. |
| T1083 File and Directory Discovery |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained information about the configured Exchange virtual directory using `Get-WebServicesVirtualDirectory`. |
| T1083 File and Directory Discovery |
CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace enumerated file system details in compromised environments. |
| T1083 File and Directory Discovery |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used `dir c:\\` to search for files. |
| T1083 File and Directory Discovery |
CampaignSalesforce Data Exfiltration | During Salesforce Data Exfiltration, threat actors queried customers' Salesforce environments to identify sensitive information for exfiltration. |
| T1083 File and Directory Discovery |
Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries obtained the contents of users’ directories using `dir /s /b C:\Users` command. |
| T1083 File and Directory Discovery |
CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system. |
| T1083 File and Directory Discovery |
CampaignOperation Wocao | During Operation Wocao, threat actors gathered a recursive directory listing to find files and directories of interest. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.