Technique.View on attack.mitre.org
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate. Custom tools may also be used to gather file and directory information and interact with the Native API. Adversaries may also leverage a Network Device CLI on network devices to gather file and directory information (e.g. dir, show flash, and/or nvram).
Some files and directories may require elevated or specific user permissions to access.
Rules on DetectionCode tagged with T1083.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Linux Auditd Database File And Directory Discovery | Anomaly | NULL | Linux Auditd Execve |
| Linux Auditd File And Directory Discovery | Anomaly | NULL | Linux Auditd Execve |
| Linux Auditd Hidden Files And Directories Creation | Anomaly | NULL | Linux Auditd Execve |
| Linux Auditd Virtual Disk File And Directory Discovery | Anomaly | NULL | Linux Auditd Execve |
| Used by | Procedure example |
|---|---|
| Groupadmin@338 | admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about files and directories: |
| GroupAoqin Dragon | Aoqin Dragon has run scripts to identify file formats including Microsoft Word. |
| GroupAPT18 | APT18 can list files information for specific directories. |
| GroupAPT28 | APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection. The group also searched a compromised DCCC computer for specific terms. |
| GroupAPT3 | APT3 has a tool that looks for files and directories on the local file system. |
| GroupAPT32 | APT32's backdoor possesses the capability to list files and directories on a machine. |
| GroupAPT38 | APT38 have enumerated files and directories, or searched in specific locations within a compromised host. |
| GroupAPT39 | APT39 has used tools with the ability to search for files on a compromised host. |
| Used by | Procedure example |
|---|---|
| Malware3PARA RAT | 3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory. |
| Malware4H RAT | 4H RAT has the capability to obtain file and directory listings. |
| MalwareAcidPour | AcidPour can identify specific files and directories within the Linux operating system corresponding with storage devices for follow-on wiping activity, similar to AcidRain. |
| MalwareAcidRain | AcidRain identifies specific files and directories in the Linux operating system associated with storage devices. |
| MalwareAction RAT | Action RAT has the ability to collect drive and file information on an infected machine. |
| MalwareADVSTORESHELL | ADVSTORESHELL can list files and directories. |
| MalwareAkira | Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as |
| MalwareAkira _v2 | Akira _v2 can target specific files and folders for encryption. |
View all 308 software examples
| Used by | Procedure example |
|---|---|
| Campaign2025 Poland Wiper Attacks | During the 2025 Poland Wiper Attacks, the adversaries obtained the contents of users’ directories using `dir /s /b C:\Users` command. |
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to identify sensitive data within the victim environment for extraction. |
| CampaignC0015 | During C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful. |
| CampaignKV Botnet Activity | KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: |
| CampaignNight Dragon | During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system. |
| CampaignOperation AkaiRyū | During Operation AkaiRyū, MirrorFace enumerated file system details in compromised environments. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used `dir c:\\` to search for files. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.