ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1083×

13 examples

TechniqueUsed byProcedure example
T1083
File and Directory Discovery
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters.

T1083
File and Directory Discovery
CampaignKV Botnet Activity

KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: \/usr\/sbin\/, \/usr\/bin\/, \/sbin\/, \/pfrm2.0\/bin\/, \/usr\/local\/bin\/.

T1083
File and Directory Discovery
CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors leveraged commands to locate accessible file shares, backup paths, or SharePoint content.

T1083
File and Directory Discovery
CampaignOperation Honeybee

During Operation Honeybee, the threat actors used a malicious DLL to search for files with specific keywords.

T1083
File and Directory Discovery
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to identify sensitive data within the victim environment for extraction.

T1083
File and Directory Discovery
CampaignC0015

During C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful.

T1083
File and Directory Discovery
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained information about the configured Exchange virtual directory using `Get-WebServicesVirtualDirectory`.

T1083
File and Directory Discovery
CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace enumerated file system details in compromised environments.

T1083
File and Directory Discovery
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used `dir c:\\` to search for files.

T1083
File and Directory Discovery
CampaignSalesforce Data Exfiltration

During Salesforce Data Exfiltration, threat actors queried customers' Salesforce environments to identify sensitive information for exfiltration.

T1083
File and Directory Discovery
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries obtained the contents of users’ directories using `dir /s /b C:\Users` command.

T1083
File and Directory Discovery
CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system.

T1083
File and Directory Discovery
CampaignOperation Wocao

During Operation Wocao, threat actors gathered a recursive directory listing to find files and directories of interest.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.