1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1083 File and Directory Discovery — Detection Rules

Detection workspace for T1083 File and Directory Discovery: 22 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1083 File and Directory Discovery

COUNT(directory_listing_or_object_list BY actor, 5m) >= threshold -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0370 Recursive Enumeration of Files and Directories Across Privilege Contexts

AN1040 Analytic 1040

Execution of file enumeration commands (e.g., 'dir', 'tree') from non-standard processes or unusual user contexts, followed by recursive directory traversal or access to sensitive locations.

AN1041 Analytic 1041

Use of file enumeration commands (e.g., 'ls', 'find', 'locate') executed by suspicious users or scripts accessing broad file hierarchies or restricted directories.

AN1042 Analytic 1042

Execution of file or directory discovery commands (e.g., 'ls', 'find') from terminal or script-based tooling, especially outside normal user workflows.

AN1043 Analytic 1043

Execution of esxcli commands to enumerate datastore, configuration files, or directory structures by unauthorized or remote users.

AN1044 Analytic 1044

Execution of file discovery commands (e.g., 'dir', 'show flash', 'nvram:') from CLI interfaces, especially by unauthorized users or from abnormal source IPs.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1083 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.