1200KM / detection
T1083 File and Directory Discovery — Detection Rules
Detection workspace for T1083 File and Directory Discovery: 22 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Linux Capabilities Discovery · test · low · {"product":"linux","service":"auditd"}
- Shell Invocation via Apt - Linux · test · medium · {"category":"process_creation","product":"linux"}
- Capabilities Discovery - Linux · test · low · {"category":"process_creation","product":"linux"}
- File and Directory Discovery - Linux · test · informational · {"category":"process_creation","product":"linux"}
- Shell Execution via Find - Linux · test · high · {"category":"process_creation","product":"linux"}
- Shell Execution via Flock - Linux · test · high · {"category":"process_creation","product":"linux"}
- Shell Execution GCC - Linux · test · high · {"category":"process_creation","product":"linux"}
- Shell Execution via Nice - Linux · test · high · {"category":"process_creation","product":"linux"}
- PUA - TruffleHog Execution - Linux · experimental · medium · {"category":"process_creation","product":"linux"}
- Potential Discovery Activity Using Find - Linux · test · medium · {"category":"process_creation","product":"linux"}
- Vim GTFOBin Abuse - Linux · test · high · {"category":"process_creation","product":"linux"}
- File and Directory Discovery - MacOS · test · informational · {"category":"process_creation","product":"macos"}
- Potential Discovery Activity Using Find - MacOS · test · medium · {"category":"process_creation","product":"macos"}
- Cisco Discovery · test · low · {"product":"cisco","service":"aaa"}
- Source Code Enumeration Detection by Keyword · test · medium · {"category":"webserver"}
- Powershell Sensitive File Discovery · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Powershell Directory Enumeration · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- DirLister Execution · test · low · {"category":"process_creation","product":"windows"}
- HackTool - PCHunter Execution · test · high · {"category":"process_creation","product":"windows"}
- Notepad Password Files Discovery · experimental · low · {"product":"windows","category":"process_creation"}
- PUA - Seatbelt Execution · test · high · {"category":"process_creation","product":"windows"}
- PUA - TruffleHog Execution · experimental · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1083 File and Directory Discovery
COUNT(directory_listing_or_object_list BY actor, 5m) >= threshold -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0370 Recursive Enumeration of Files and Directories Across Privilege Contexts
AN1040 Analytic 1040
Execution of file enumeration commands (e.g., 'dir', 'tree') from non-standard processes or unusual user contexts, followed by recursive directory traversal or access to sensitive locations.
AN1041 Analytic 1041
Use of file enumeration commands (e.g., 'ls', 'find', 'locate') executed by suspicious users or scripts accessing broad file hierarchies or restricted directories.
AN1042 Analytic 1042
Execution of file or directory discovery commands (e.g., 'ls', 'find') from terminal or script-based tooling, especially outside normal user workflows.
AN1043 Analytic 1043
Execution of esxcli commands to enumerate datastore, configuration files, or directory structures by unauthorized or remote users.
AN1044 Analytic 1044
Execution of file discovery commands (e.g., 'dir', 'show flash', 'nvram:') from CLI interfaces, especially by unauthorized users or from abnormal source IPs.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Turla · G0010
- Darkhotel · G0012
- admin@338 · G0018
- APT3 · G0022
- APT18 · G0026
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- Patchwork · G0040
- Winnti Group · G0044
- menuPass · G0045
- Gamaredon Group · G0047
- APT32 · G0050
- Sowbug · G0054
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- MuddyWater · G0069
- Dark Caracal · G0070
- Leafminer · G0077
- Tropic Trooper · G0081
- APT38 · G0082
- APT39 · G0087
- Kimsuky · G0094
- APT41 · G0096
- Inception · G0100
- Chimera · G0114
- Fox Kitten · G0117
- Sidewinder · G0121
- Windigo · G0124
- HAFNIUM · G0125
- Mustang Panda · G0129
- TeamTNT · G0139
- Confucius · G0142
- Aoqin Dragon · G1007
- LuminousMoth · G1014
- Scattered Spider · G1015
- FIN13 · G1016
- Volt Typhoon · G1017
- ToddyCat · G1022
- APT5 · G1023
- Winter Vivern · G1035
- RedCurl · G1039
- Play · G1040
- Velvet Ant · G1047
- UNC3886 · G1048
- Medusa Group · G1051
- Contagious Interview · G1052
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.