T1083 File and Directory Discovery — ATT&CK Technique
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate. Custom tools may also be used to gather file and directory information and interact with the Native API. Adversaries may also leverage a Network Device CLI on network devices to gather file and directory information (e.g. dir, show flash, and/or nvram). Some files and directories may require elevated or specific user permissions to access.
Detection coverage (28)
- Turla Group Lateral Movement critical
- WannaCry Ransomware Activity critical
- Vim GTFOBin Abuse - Linux high
- Linux Capabilities Discovery low
- Shell Invocation via Apt - Linux medium
- Capabilities Discovery - Linux low
- File and Directory Discovery - Linux informational
- Shell Execution via Find - Linux high
- Shell Execution via Flock - Linux high
- Shell Execution GCC - Linux high
- Shell Execution via Nice - Linux high
- Potential Discovery Activity Using Find - Linux medium
- File and Directory Discovery - MacOS informational
- Potential Discovery Activity Using Find - MacOS medium
- PUA - TruffleHog Execution medium
- Cisco Discovery low
- PUA - Seatbelt Execution high
- PUA - TruffleHog Execution - Linux medium
- Source Code Enumeration Detection by Keyword medium
- Powershell Sensitive File Discovery medium
- Powershell Directory Enumeration medium
- DirLister Execution low
- HackTool - PCHunter Execution high
- Notepad Password Files Discovery low
- Linux Auditd Database File And Directory Discovery
- Linux Auditd File And Directory Discovery
- Linux Auditd Hidden Files And Directories Creation
- Linux Auditd Virtual Disk File And Directory Discovery
Malware using this technique
- Orz
- Attor
- USBStealer
- SDBbot
- Kinsing
- Amadey
- Woody RAT
- PlugX
- Akira
- Volgmer
- AshTag
- P.A.S. Webshell
- Bazar
- SLOTHFULMEDIA
- ADVSTORESHELL
- FinFisher
- Crimson
- SynAck
- yty
- TAINTEDSCRIBE
- ELMER
- SUGARDUMP
- Fysbis
- Remsec
- KillDisk
- InvisibleFerret
- Embargo
- Trojan.Karagany
- PoshC2
- WinMM
- Turian
- POORAIM
- Micropsia
- Misdat
- Winnti for Windows
- GeminiDuke
- BoxCaon
- LazyWiper
- njRAT
- PinchDuke
- WindTail
- AuditCred
- Diavol
- Sliver
- PowerDuke
- BackConfig
- Bankshot
- PingPull
- 4H RAT
- FALLCHILL
Threat actors using this technique
- Confucius
- Anubis
- APT41
- Winnti Group
- Winter Vivern
- Volt Typhoon
- Contagious Interview
- UNC3886
- Patchwork
- Sowbug
- Gamaredon Group
- APT5
- Dragonfly
- APT38
- APT28
- Windigo
- Inception
- MirrorFace
- RedCurl
- Velvet Ant
- APT18
- Chimera
- admin@338
- APT15
- Sandworm Team
- Sidewinder
- Scattered Spider
- Aoqin Dragon
- Tropic Trooper
- Dark Caracal
- MuddyWater
- APT35
- TeamTNT
- Lotus Blossom
- APT3
- APT32
- Mustang Panda
- APT39
- ToddyCat
- Lazarus Group
- Darkhotel
- APT10
- Medusa Ransomware
- Termite
- Play Ransomware
- Kimsuky
- HAFNIUM
- Fox Kitten
- Leafminer
- FIN13