Cross-source coverage
T1083 / ATT&CK
File and Directory Discovery
195 rules · 187 families across 10 sources.
Showing deprecated rules · back to the default
From MITRE ATT&CK 19.2
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate. Custom tools may also be used to gather file and directory information and interact with the Native API. Adversaries may also leverage a Network Device CLI on network devices to gather file and directory information (e.g. dir, show flash, and/or nvram).
Some files and directories may require elevated or specific user permissions to access.
- Tactics
- Discovery
- Platforms
- ESXi · Linux · macOS · Network Devices · Windows
- Telemetry
-
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLauditd:PATHmacos:unifiedlogfs:fsusageesxi:shellesxi:hostdnetworkdevice:syslog
How MITRE says to detect it DET0370
Recursive Enumeration of Files and Directories Across Privilege Contexts
Windows Analytic 1040
Execution of file enumeration commands (e.g., 'dir', 'tree') from non-standard processes or unusual user contexts, followed by recursive directory traversal or access to sensitive locations.
WinEventLog:SecurityEventCode=4688WinEventLog:SysmonEventCode=11
Linux Analytic 1041
Use of file enumeration commands (e.g., 'ls', 'find', 'locate') executed by suspicious users or scripts accessing broad file hierarchies or restricted directories.
auditd:SYSCALLexecveauditd:PATHPATH
macOS Analytic 1042
Execution of file or directory discovery commands (e.g., 'ls', 'find') from terminal or script-based tooling, especially outside normal user workflows.
macos:unifiedloglog collect --predicatefs:fsusageFilesystem Call Monitoring
ESXi Analytic 1043
Execution of esxcli commands to enumerate datastore, configuration files, or directory structures by unauthorized or remote users.
esxi:shellShell Access/Command Executionesxi:hostdvSphere File API Access
Network Devices Analytic 1044
Execution of file discovery commands (e.g., 'dir', 'show flash', 'nvram:') from CLI interfaces, especially by unauthorized users or from abnormal source IPs.
networkdevice:syslogCLI Command Logging
Emerging Threats Open
100 rules · 93 families+ 90 more from Emerging Threats Open → showing the 10 highest-severity
SigmaHQ/sigma
24 rules| Detection | Severity | Format |
|---|---|---|
| Turla Group Lateral Movement | Critical | Sigma |
| WannaCry Ransomware Activity | Critical | Sigma |
| HackTool - PCHunter Execution | High | Sigma |
| PUA - Seatbelt Execution | High | Sigma |
| Shell Execution GCC - Linux | High | Sigma |
| Shell Execution via Find - Linux | High | Sigma |
| Shell Execution via Flock - Linux | High | Sigma |
| Shell Execution via Nice - Linux | High | Sigma |
| Vim GTFOBin Abuse - Linux | High | Sigma |
| Potential Discovery Activity Using Find - Linux | Medium | Sigma |
+ 14 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
23 rules| Detection | Severity | Format |
|---|---|---|
| AWS Credentials Searched For Inside A Container | High | Elastic TOML |
| Potential Credential Discovery via Recursive Grep | High | Elastic TOML |
| Private Key Searching Activity | High | Elastic TOML |
| Suspicious Dynamic Linker Discovery via od | High | Elastic TOML |
| Suspicious Memory grep Activity | High | Elastic TOML |
| Cloud Credential Search Detected via Defend for Containers | Medium | Elastic TOML |
| ESXI Discovery via Find | Medium | Elastic TOML |
| ESXI Discovery via Grep | Medium | Elastic TOML |
| Full Disk Access Permission Check | Medium | Elastic TOML |
| Process Capability Enumeration | Medium | Elastic TOML |
+ 13 more from elastic/detection-rules → showing the 10 highest-severity
socfortress/Wazuh-Rules
18 rules · 17 families| Detection | Severity | Format |
|---|---|---|
| Sysmon - Event 1: Process creation · CMD DIR enumeration (T1083) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · CMD TREE command (T1083) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · DirLister tool execution (T1083) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · ESXi file enumeration via plink (T1083) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell gci recursive (T1083) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell Get-ChildItem recursive (T1083) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell ls recursive (T1083) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · PowerShell MAZE-style folder discovery (T1083) | High | Wazuh XML |
| OPNsense NAXSI - event blocked by WAF | Medium | Wazuh XML |
| Possible File and Directory Discovery (MITRE T1083) | Medium | Wazuh XML |
+ 8 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
Wazuh Core Ruleset
17 rules| Detection | Severity | Format |
|---|---|---|
| Multiple common web attacks from same source ip. | High | Wazuh XML |
| Netscaler: Multiple http resource access denied | High | Wazuh XML |
| Netscaler: Multiple non-http resource access denied | High | Wazuh XML |
| or directory from same source ip. | High | Wazuh XML |
| Squid: Multiple attempts to access a non-existent file. | High | Wazuh XML |
| Common web attack. | Medium | Wazuh XML |
| Executed recursive query of all files using ls command. | Medium | Wazuh XML |
| ModSecurity rejected a query | Medium | Wazuh XML |
| ModSecurity: Rejected a query | Medium | Wazuh XML |
| NAXSI rejected a query | Medium | Wazuh XML |
+ 7 more from Wazuh Core Ruleset → showing the 10 highest-severity
chronicle/detection-rules
4 rules| Detection | Severity | Format |
|---|---|---|
| backdoor_detection_on_sql_servers | Undefined | YARA-L |
| detect_possible_discovery_and_collection_of_files | Undefined | YARA-L |
| detect_search_for_credentials_on_windows_operating_system | Undefined | YARA-L |
| hostdomain_enumeration_with_wmic | Undefined | YARA-L |
splunk/security_content
4 rules| Detection | Severity | Format |
|---|---|---|
| Linux Auditd Database File And Directory Discovery | Undefined | SPL |
| Linux Auditd File And Directory Discovery | Undefined | SPL |
| Linux Auditd Hidden Files And Directories Creation | Undefined | SPL |
| Linux Auditd Virtual Disk File And Directory Discovery | Undefined | SPL |
elastic/protections-artifacts
3 rules| Detection | Severity | Format |
|---|---|---|
| Multi-Value Secret Searching via Find | Undefined | Elastic TOML |
| Multi-Value Secret Searching via Grep | Undefined | Elastic TOML |
| Potential SUID/SGID Files Enumeration | Undefined | Elastic TOML |
falcosecurity/rules
1 rule| Detection | Severity | Format |
|---|---|---|
| Read environment variable from /proc files | Medium | Falco YAML |
panther-labs/panther-analysis
1 rule| Detection | Severity | Format |
|---|---|---|
| AWS WAF Managed Admin Protection Passthrough Rule | High | Panther Python |