File and Directory Discovery

T1083

Technique.View on attack.mitre.org

About this technique

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate. Custom tools may also be used to gather file and directory information and interact with the Native API. Adversaries may also leverage a Network Device CLI on network devices to gather file and directory information (e.g. dir, show flash, and/or nvram).

Some files and directories may require elevated or specific user permissions to access.

Detection rules26

Rules on DetectionCode tagged with T1083.

Sigma22

RuleLevelLog source
HackTool - PCHunter Executionhighwindows / process_creation
PUA - Seatbelt Executionhighwindows / process_creation
Shell Execution GCC - Linuxhighlinux / process_creation
Shell Execution via Find - Linuxhighlinux / process_creation
Shell Execution via Flock - Linuxhighlinux / process_creation
Shell Execution via Nice - Linuxhighlinux / process_creation
Vim GTFOBin Abuse - Linuxhighlinux / process_creation
Potential Discovery Activity Using Find - Linuxmediumlinux / process_creation
Potential Discovery Activity Using Find - MacOSmediummacos / process_creation
Powershell Directory Enumerationmediumwindows / ps_script
Powershell Sensitive File Discoverymediumwindows / ps_script
PUA - TruffleHog Executionmediumwindows / process_creation
PUA - TruffleHog Execution - Linuxmediumlinux / process_creation
Shell Invocation via Apt - Linuxmediumlinux / process_creation
Source Code Enumeration Detection by KeywordmediumNULL / webserver

Splunk4

RuleTypeRiskData source
Linux Auditd Database File And Directory DiscoveryAnomalyNULLLinux Auditd Execve
Linux Auditd File And Directory DiscoveryAnomalyNULLLinux Auditd Execve
Linux Auditd Hidden Files And Directories CreationAnomalyNULLLinux Auditd Execve
Linux Auditd Virtual Disk File And Directory DiscoveryAnomalyNULLLinux Auditd Execve

Groups52

Show 28 more

Software308

Show 284 more
BACKSPACEBADFLICKBADNEWSBadPatchBandookBankshotBazarBBSRATBeaverTailBisonalBlack BastaBlackCatBLACKCOFFEEBlackEnergyBlackMouldBLINDINGCANBLUELIGHTBOLDMOVEBoomBoxBoxCaonBrave PrinceBRICKSTORMCaddyWiperCanisterWormCannonCardinal RATCaterpillar WebShellccf32CharmPowerChChesCheerscryptCHIMNEYSWEEPChina ChopperCHOPSTICKClamblingClopcmdCOATHANGERCobalt StrikeContiCookieMinerCORALDECKCosmicDukeCrackMapExecCreepyDriveCrimsonCrossRATCryptoisticCubaCuckoo StealerCyclops BlinkDaclsDarkGateDarkWatchmanDDKONGDEATHRANSOMDenisDerusbiDiavolDiskpartDokidown_newDropBookDtrackDUSTTRAPDustySkyDynoWiperEliseELMEREmbargoEmpireEpicExbyteFALLCHILLFatDukeFinFisherFIVEHANDSFLASHFLOODFoggyWebForfilesFruitFlyFunnyDreamFYAntiFysbisGelsemiumGeminiDukeGold DragonGoldenSpyGomirGravityRATGrimAgentHavocHermeticWiperHeyoka BackdoorHOPLIGHTHotCroissantHTTPBrowserHydraqIceAppleImminent MonitorINC RansomwareIndustroyerInnaputRATInvisibleFerretInvisiMoleIxesheJPINjRATKasidetKazuarKeyBoyKEYMARBLEKGH_SPYKillDiskKinsingKivarsKoadicKONNIKwampirsLAMEHUGLatrodectusLazyWiperLightSpyLinfoLITTLELAMB.WOOLTEALockBit 2.0LockBit 3.0LODEINFOLoFiSeLokibotLookBackLunarMailLunarWebMacheteMacMaMafaldaMangoManjusakaMarkiRATMedusa RansomwareMegaCortexMegazordMESSAGETAPmetaMainMetamorfoMicropsiaMini Shai-HuludMiniDukeMisdatMispaduMobileOrderMoonWindMultiLayer WiperNDiskMonitorNebulaeNETEAGLENETWIRENightClubNinjanjRATNotPetyaObliqueRATOceanSaltOctopusODAgentOkrumOrzOSX/ShlayerOutSteelOwaAuthP.A.S. WebshellPACEMAKERPasamPcexterPenquinPeppyPinchDukePingPullPisloaderPlaycryptPLEADPlugXPoetRATPOORAIMPoshC2PowerDukePOWRUNERPrestigePrikormkaProxysvcPsyloPteranodonPupyQakBotQilinQuietSieveRaccoon StealerRainyDayRamsayRansomHubRARSTONERaspberry RobinRcloneRedLeavesRemcosRemexiRemoteUtilitiesRemsecREvilRising SunROADSWEEPROKRATRoverRoyalRTMRyukSaint BotSameCoinSamuraiSDBbotSeasaltSharpDiscoShimRatSHOTPUTSideTwistSILENTTRINITYSiloscapeSkidmapSliverSLOTHFULMEDIASmoke LoaderSombRATSoreFangSOUNDBITESPACESHIPSpicaSplatCloakStealBitStreamExStrifeWaterStrongPityStuxnetSUGARDUMPSUNBURSTSUNSPOTSynAckSysUpdateTaidoorTAINTEDSCRIBETajMahalTeamPCP Cloud StealerThreatNeedleTINYTYPHONTrickBotTrojan.KaraganyTroll StealerTruffleHogTSCookieTurianTYPEFRAMEUPPERCUTUroburosUSBferryUSBStealerVolgmerWannaCryWarzoneRATWastedLockerWhisperGateWindTailWINERACKWinMMWinnti for WindowsWoody RATXAgentOSXXCSSETytyZebrocyZeus PandaZIPLINEZLibZoxzwShellZxShell

Campaigns13

Procedure examples373

Groups52

Used byProcedure example
Groupadmin@338

admin@338 actors used the following commands after exploiting a machine with LOWBALL malware to obtain information about files and directories: dir c:\ >> %temp%\download dir "c:\Documents and Settings" >> %temp%\download dir "c:\Program Files\" >> %temp%\download dir d:\ >> %temp%\download

GroupAoqin Dragon

Aoqin Dragon has run scripts to identify file formats including Microsoft Word.

GroupAPT18

APT18 can list files information for specific directories.

GroupAPT28

APT28 has used Forfiles to locate PDF, Excel, and Word documents during collection. The group also searched a compromised DCCC computer for specific terms.

GroupAPT3

APT3 has a tool that looks for files and directories on the local file system.

GroupAPT32

APT32's backdoor possesses the capability to list files and directories on a machine.

GroupAPT38

APT38 have enumerated files and directories, or searched in specific locations within a compromised host.

GroupAPT39

APT39 has used tools with the ability to search for files on a compromised host.

View all 52 groups examples

Software308

Used byProcedure example
Malware3PARA RAT

3PARA RAT has a command to retrieve metadata for files on disk as well as a command to list the current working directory.

Malware4H RAT

4H RAT has the capability to obtain file and directory listings.

MalwareAcidPour

AcidPour can identify specific files and directories within the Linux operating system corresponding with storage devices for follow-on wiping activity, similar to AcidRain.

MalwareAcidRain

AcidRain identifies specific files and directories in the Linux operating system associated with storage devices.

MalwareAction RAT

Action RAT has the ability to collect drive and file information on an infected machine.

MalwareADVSTORESHELL

ADVSTORESHELL can list files and directories.

MalwareAkira

Akira examines files prior to encryption to determine if they meet requirements for encryption and can be encrypted by the ransomware. These checks are performed through native Windows functions such as GetFileAttributesW.

MalwareAkira _v2

Akira _v2 can target specific files and folders for encryption.

View all 308 software examples

Campaigns13

Used byProcedure example
Campaign2025 Poland Wiper Attacks

During the 2025 Poland Wiper Attacks, the adversaries obtained the contents of users’ directories using `dir /s /b C:\Users` command.

CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary leveraged Claude Code to identify sensitive data within the victim environment for extraction.

CampaignC0015

During C0015, the threat actors conducted a file listing discovery against multiple hosts to ensure locker encryption was successful.

CampaignKV Botnet Activity

KV Botnet Activity gathers a list of filenames from the following locations during execution of the final botnet stage: \/usr\/sbin\/, \/usr\/bin\/, \/sbin\/, \/pfrm2.0\/bin\/, \/usr\/local\/bin\/.

CampaignNight Dragon

During Night Dragon, threat actors used zwShell to establish full remote control of the connected machine and browse the victim file system.

CampaignOperation AkaiRyū

During Operation AkaiRyū, MirrorFace enumerated file system details in compromised environments.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used `dir c:\\` to search for files.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group conducted word searches within documents on a compromised host in search of security and financial matters.

View all 13 campaigns examples

References2

  1. US-CERT-TA18-106A Open source
    US-CERT. (2018, April 20). Alert (TA18-106A) Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.
  2. Windows Commands JPCERT Open source
    Tomonaga, S. (2016, January 26). Windows Commands Abused by Attackers. Retrieved February 2, 2016.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.