Cross-source coverage

T1083 / ATT&CK

File and Directory Discovery

195 rules · 187 families across 10 sources.

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate. Custom tools may also be used to gather file and directory information and interact with the Native API. Adversaries may also leverage a Network Device CLI on network devices to gather file and directory information (e.g. dir, show flash, and/or nvram).

Some files and directories may require elevated or specific user permissions to access.

Tactics
Discovery
Platforms
ESXi · Linux · macOS · Network Devices · Windows
Telemetry
WinEventLog:SecurityWinEventLog:Sysmonauditd:SYSCALLauditd:PATHmacos:unifiedlogfs:fsusageesxi:shellesxi:hostdnetworkdevice:syslog

How MITRE says to detect it DET0370

Recursive Enumeration of Files and Directories Across Privilege Contexts

Windows Analytic 1040

Execution of file enumeration commands (e.g., 'dir', 'tree') from non-standard processes or unusual user contexts, followed by recursive directory traversal or access to sensitive locations.

  • WinEventLog:Security EventCode=4688
  • WinEventLog:Sysmon EventCode=11

Linux Analytic 1041

Use of file enumeration commands (e.g., 'ls', 'find', 'locate') executed by suspicious users or scripts accessing broad file hierarchies or restricted directories.

  • auditd:SYSCALL execve
  • auditd:PATH PATH

macOS Analytic 1042

Execution of file or directory discovery commands (e.g., 'ls', 'find') from terminal or script-based tooling, especially outside normal user workflows.

  • macos:unifiedlog log collect --predicate
  • fs:fsusage Filesystem Call Monitoring

ESXi Analytic 1043

Execution of esxcli commands to enumerate datastore, configuration files, or directory structures by unauthorized or remote users.

  • esxi:shell Shell Access/Command Execution
  • esxi:hostd vSphere File API Access

Network Devices Analytic 1044

Execution of file discovery commands (e.g., 'dir', 'show flash', 'nvram:') from CLI interfaces, especially by unauthorized users or from abnormal source IPs.

  • networkdevice:syslog CLI Command Logging

Emerging Threats Open

100 rules · 93 families
Detection Severity Format
ET EXPLOIT aiohttp Directory Traversal in Static Routing (CVE-2024-23334) High Suricata
ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M1 3 variants High Suricata
ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M2 3 variants High Suricata
ET EXPLOIT Apache HTTP Server 2.4.49 - Path Traversal Attempt (CVE-2021-41773) M3 3 variants High Suricata
ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M1 2 variants High Suricata
ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (CVE-2021-42013) M2 2 variants High Suricata
ET EXPLOIT Apache HTTP Server - Path Traversal Attempt (Unassigned CVE) High Suricata
ET EXPLOIT Attempted Directory Traversal via HTTP Cookie (CVE-2020-9484) High Suricata
ET EXPLOIT Aviatrix Controller Unrestricted File Upload with Path Traversal Inbound (CVE-2021-40870) High Suricata
ET EXPLOIT Cisco Adaptive Security Appliance - Path Traversal High Suricata

+ 90 more from Emerging Threats Open → showing the 10 highest-severity

SigmaHQ/sigma

24 rules
Detection Severity Format
Turla Group Lateral Movement Critical Sigma
WannaCry Ransomware Activity Critical Sigma
HackTool - PCHunter Execution High Sigma
PUA - Seatbelt Execution High Sigma
Shell Execution GCC - Linux High Sigma
Shell Execution via Find - Linux High Sigma
Shell Execution via Flock - Linux High Sigma
Shell Execution via Nice - Linux High Sigma
Vim GTFOBin Abuse - Linux High Sigma
Potential Discovery Activity Using Find - Linux Medium Sigma

+ 14 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

23 rules
Detection Severity Format
AWS Credentials Searched For Inside A Container High Elastic TOML
Potential Credential Discovery via Recursive Grep High Elastic TOML
Private Key Searching Activity High Elastic TOML
Suspicious Dynamic Linker Discovery via od High Elastic TOML
Suspicious Memory grep Activity High Elastic TOML
Cloud Credential Search Detected via Defend for Containers Medium Elastic TOML
ESXI Discovery via Find Medium Elastic TOML
ESXI Discovery via Grep Medium Elastic TOML
Full Disk Access Permission Check Medium Elastic TOML
Process Capability Enumeration Medium Elastic TOML

+ 13 more from elastic/detection-rules → showing the 10 highest-severity

socfortress/Wazuh-Rules

18 rules · 17 families
Detection Severity Format
Sysmon - Event 1: Process creation · CMD DIR enumeration (T1083) High Wazuh XML
Sysmon - Event 1: Process creation · CMD TREE command (T1083) High Wazuh XML
Sysmon - Event 1: Process creation · DirLister tool execution (T1083) High Wazuh XML
Sysmon - Event 1: Process creation · ESXi file enumeration via plink (T1083) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell gci recursive (T1083) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell Get-ChildItem recursive (T1083) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell ls recursive (T1083) High Wazuh XML
Sysmon - Event 1: Process creation · PowerShell MAZE-style folder discovery (T1083) High Wazuh XML
OPNsense NAXSI - event blocked by WAF Medium Wazuh XML
Possible File and Directory Discovery (MITRE T1083) Medium Wazuh XML

+ 8 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

Wazuh Core Ruleset

17 rules
Detection Severity Format
Multiple common web attacks from same source ip. High Wazuh XML
Netscaler: Multiple http resource access denied High Wazuh XML
Netscaler: Multiple non-http resource access denied High Wazuh XML
or directory from same source ip. High Wazuh XML
Squid: Multiple attempts to access a non-existent file. High Wazuh XML
Common web attack. Medium Wazuh XML
Executed recursive query of all files using ls command. Medium Wazuh XML
ModSecurity rejected a query Medium Wazuh XML
ModSecurity: Rejected a query Medium Wazuh XML
NAXSI rejected a query Medium Wazuh XML

+ 7 more from Wazuh Core Ruleset → showing the 10 highest-severity

chronicle/detection-rules

4 rules
Detection Severity Format
backdoor_detection_on_sql_servers Undefined YARA-L
detect_possible_discovery_and_collection_of_files Undefined YARA-L
detect_search_for_credentials_on_windows_operating_system Undefined YARA-L
hostdomain_enumeration_with_wmic Undefined YARA-L

splunk/security_content

4 rules
Detection Severity Format
Linux Auditd Database File And Directory Discovery Undefined SPL
Linux Auditd File And Directory Discovery Undefined SPL
Linux Auditd Hidden Files And Directories Creation Undefined SPL
Linux Auditd Virtual Disk File And Directory Discovery Undefined SPL

elastic/protections-artifacts

3 rules
Detection Severity Format
Multi-Value Secret Searching via Find Undefined Elastic TOML
Multi-Value Secret Searching via Grep Undefined Elastic TOML
Potential SUID/SGID Files Enumeration Undefined Elastic TOML

falcosecurity/rules

1 rule
Detection Severity Format
Read environment variable from /proc files Medium Falco YAML

panther-labs/panther-analysis

1 rule
Detection Severity Format
AWS WAF Managed Admin Protection Passthrough Rule High Panther Python

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.