Real-world descriptions of how a group, tool or campaign used a technique.
308 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareTrickBot | TrickBot searches the system for all of the following file extensions: .avi, .mov, .mkv, .mpeg, .mpeg4, .mp4, .mp3, .wav, .ogg, .jpeg, .jpg, .png, .bmp, .gif, .tiff, .ico, .xlsx, and .zip. It can also obtain browsing history, cookies, and plug-in information. |
| T1083 File and Directory Discovery |
MalwarePowerDuke | PowerDuke has commands to get the current directory name as well as the size of a file. It also has commands to obtain information about logical drives, drive type, and free space. |
| T1083 File and Directory Discovery |
MalwareBLINDINGCAN | BLINDINGCAN can search, read, write, move, and execute files. |
| T1083 File and Directory Discovery |
MalwareNinja | Ninja has the ability to enumerate directory content. |
| T1083 File and Directory Discovery |
MalwareQuietSieve | QuietSieve can search files on the target host by extension, including doc, docx, xls, rtf, odt, txt, jpg, pdf, rar, zip, and 7z. |
| T1083 File and Directory Discovery |
MalwareSynAck | SynAck checks its directory location in an attempt to avoid launching in a sandbox. |
| T1083 File and Directory Discovery |
MalwareBRICKSTORM | BRICKSTORM has identified specific files and directories within targeted hosts and systems for modification, execution, collection and exfiltration. |
| T1083 File and Directory Discovery |
MalwareAcidRain | AcidRain identifies specific files and directories in the Linux operating system associated with storage devices. |
| T1083 File and Directory Discovery |
MalwareAmadey | Amadey has searched for folders associated with antivirus software. |
| T1083 File and Directory Discovery |
MalwareProxysvc | Proxysvc lists files in directories. |
| T1083 File and Directory Discovery |
MalwareOrz | Orz can gather victim drive information. |
| T1083 File and Directory Discovery |
Malwareyty | yty gathers information on victim’s drives and has a plugin for document listing. |
| T1083 File and Directory Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects information about available drives, default browser, desktop file list, My Documents, Internet history, program files, and root of available drives. It also searches for ICS-related software files. |
| T1083 File and Directory Discovery |
MalwareStuxnet | Stuxnet uses a driver to scan for specific filesystem driver objects. |
| T1083 File and Directory Discovery |
MalwareAvosLocker | AvosLocker has searched for files and directories on a compromised network. |
| T1083 File and Directory Discovery |
MalwarePOWRUNER | POWRUNER may enumerate user directories on a victim. |
| T1083 File and Directory Discovery |
MalwareCOATHANGER | COATHANGER will survey the contents of system files during installation. |
| T1083 File and Directory Discovery |
MalwareSmoke Loader | Smoke Loader recursively searches through directories for files. |
| T1083 File and Directory Discovery |
MalwareWindTail | WindTail has the ability to enumerate the users home directory and the path to its own application bundle. |
| T1083 File and Directory Discovery |
MalwareMisdat | Misdat is capable of running commands to obtain a list of files and directories, as well as enumerating logical drives. |
| T1083 File and Directory Discovery |
MalwareKEYMARBLE | KEYMARBLE has a command to search for files on the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareThreatNeedle | ThreatNeedle can obtain file and directory information. |
| T1083 File and Directory Discovery |
MalwareRansomHub | RansomHub has the ability to only encrypt specific files. |
| T1083 File and Directory Discovery |
MalwareZLib | ZLib has the ability to enumerate files and drives. |
| T1083 File and Directory Discovery |
MalwareRedLeaves | RedLeaves can enumerate and search for files and directories. |
| T1083 File and Directory Discovery |
MalwareLITTLELAMB.WOOLTEA | LITTLELAMB.WOOLTEA can monitor for system upgrade events by checking for the presence of `/tmp/data/root/dev`. |
| T1083 File and Directory Discovery |
MalwareZeus Panda | Zeus Panda searches for specific directories on the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareGeminiDuke | GeminiDuke collects information from the victim, including installed drivers, programs previously executed by users, programs and services configured to automatically run at startup, files and folders present in any user's home folder, files and folders present in any user's My Documents, programs installed to the Program Files folder, and recently accessed files, folders, and programs. |
| T1083 File and Directory Discovery |
MalwareHavoc | The Havoc interface can display a file explorer view of the compromised host. |
| T1083 File and Directory Discovery |
MalwareGravityRAT | GravityRAT collects the volumes mapped on the system, and also steals files with the following extensions: .docx, .doc, .pptx, .ppt, .xlsx, .xls, .rtf, and .pdf. |
| T1083 File and Directory Discovery |
MalwarePrestige | Prestige can traverse the file system to discover files to encrypt by identifying specific extensions defined in a hardcoded list. |
| T1083 File and Directory Discovery |
MalwareInvisibleFerret | InvisibleFerret has identified specific directories and files for exfiltration using the `ssh_upload` command which contains subcommands of `.sdira`, `sdir`, `sfile`, `sfinda`, `sfindr`, `sfind`. InvisibleFerret also has the capability to scan and upload files of interest from multiple OS systems through the use of scripts that check file names, file extensions, and avoids certain path names. InvisibleFerret has utilized the `findstr` on Windows or the macOS `find` commands to search for files of interest. ESET Contagious Interview BeaverTail InvisibleFerret February 2025Esentire ContagiousInterview BeaverTail InvisibleFerret November 2024PaloAlto ContagiousInterview BeaverTail InvisibleFerret November 2023PaloAlto Unit42 ContagiousInterview BeaverTail InvisibileFerret October 2024Zscaler ContagiousInterview BeaverTail InvisibleFerret November 2024 |
| T1083 File and Directory Discovery |
MalwareBankshot | Bankshot searches for files on the victim's machine. |
| T1083 File and Directory Discovery |
MalwareSharpDisco | SharpDisco can identify recently opened files by using an LNK format parser to extract the original file path from LNK files found in either `%USERPROFILE%\Recent` (Windows XP) or `%APPDATA%\Microsoft\Windows\Recent` (newer Windows versions) . |
| T1083 File and Directory Discovery |
MalwareStrongPity | StrongPity can parse the hard drive on a compromised host to identify specific file extensions. |
| T1083 File and Directory Discovery |
MalwareWinMM | WinMM sets a WH_CBT Windows hook to search for and capture files on the victim. |
| T1083 File and Directory Discovery |
MalwareNebulae | Nebulae can list files and directories on a compromised host. |
| T1083 File and Directory Discovery |
MalwareAuditCred | AuditCred can search through folders and files on the system. |
| T1083 File and Directory Discovery |
MalwareKasidet | Kasidet has the ability to search for a given filename on a victim. |
| T1083 File and Directory Discovery |
MalwareOceanSalt | OceanSalt can extract drive information from the endpoint and search files on the system. |
| T1083 File and Directory Discovery |
MalwarePlaycrypt | Playcrypt can avoid encrypting files with a .PLAY, .exe, .msi, .dll, .lnk, or .sys file extension. |
| T1083 File and Directory Discovery |
MalwareBrave Prince | Brave Prince gathers file and directory information from the victim’s machine. |
| T1083 File and Directory Discovery |
MalwareMedusa Ransomware | Medusa Ransomware has searched for files within the victim environment for encryption and exfiltration. Medusa Ransomware has also identified files associated with remote management services. |
| T1083 File and Directory Discovery |
MalwareRainyDay | RainyDay can use a file exfiltration tool to collect recently changed files with specific extensions. |
| T1083 File and Directory Discovery |
MalwareAppleSeed | AppleSeed has the ability to search for .txt, .ppt, .hwp, .pdf, and .doc files in specified directories. |
| T1083 File and Directory Discovery |
MalwareNETWIRE | NETWIRE has the ability to search for files on the compromised host. |
| T1083 File and Directory Discovery |
MalwareCosmicDuke | CosmicDuke searches attached and mounted drives for file extensions and keywords that match a predefined list. |
| T1083 File and Directory Discovery |
MalwareGomir | Gomir collects information about directory and file structures, including total number of subdirectories, total number of files, and total size of files on infected systems. |
| T1083 File and Directory Discovery |
MalwareAria-body | Aria-body has the ability to gather metadata from a file and to search for file and directory names. |
| T1083 File and Directory Discovery |
MalwareBOLDMOVE | BOLDMOVE can list information of all files in the system recursively from the root directory or from a specified directory. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.