1200KM / simulation
T1083 File and Directory Discovery — Attack Simulation
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Many command shell utilities can be used to obtain this…
Technique description
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Many command shell utilities can be used to obtain this…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- File and Directory Discovery (cmd.exe)
Procedure 0e36303b-6762-4500-b003-127743b80ba6; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Nix File and Directory Discovery 2
Procedure 13c5e1ae-605b-46c4-a79f-db28c77ff24e; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- File and Directory Discovery (PowerShell)
Procedure 2158908e-b7ef-4c21-8a83-3ce4dd05a924; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Identifying Network Shares - Linux
Procedure 361fe49d-0c19-46ec-a483-ccb92d38e88e; elevation not declared required; cleanup not declared. Not executed or individually validated.
- ESXi - Enumerate VMDKs available on an ESXi Host
Procedure 4a233a40-caf7-4cf1-890a-c6331bbc72cf; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Recursive Enumerate Files And Directories By Powershell
Procedure 95a21323-770d-434c-80cd-6f6fbf7af432; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Launch DirLister Executable
Procedure c5bec457-43c9-4a18-9a24-fe151d8971b7; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Simulating MAZE Directory Enumeration
Procedure c6c34f61-1c3e-40fb-8a58-d017d88286d8; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Nix File and Directory Discovery
Procedure ffc8b249-372a-4b74-adcd-e4c0430842de; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT28 · G0007
- Turla · G0010
- Darkhotel · G0012
- admin@338 · G0018
- APT3 · G0022
- APT18 · G0026
- Lotus Blossom · G0030
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- Patchwork · G0040
- Winnti Group · G0044
- menuPass · G0045
- Gamaredon Group · G0047
- APT32 · G0050
- Sowbug · G0054
- Magic Hound · G0059
- BRONZE BUTLER · G0060
- MuddyWater · G0069
- Dark Caracal · G0070
- Leafminer · G0077
- Tropic Trooper · G0081
- APT38 · G0082
- APT39 · G0087
- Kimsuky · G0094
- APT41 · G0096
- Inception · G0100
- Chimera · G0114
- Fox Kitten · G0117
- Sidewinder · G0121
- Windigo · G0124
- HAFNIUM · G0125
- Mustang Panda · G0129
- TeamTNT · G0139
- Confucius · G0142
- Aoqin Dragon · G1007
- LuminousMoth · G1014
- Scattered Spider · G1015
- FIN13 · G1016
- Volt Typhoon · G1017
- ToddyCat · G1022
- APT5 · G1023
- Winter Vivern · G1035
- RedCurl · G1039
- Play · G1040
- Velvet Ant · G1047
- UNC3886 · G1048
- Medusa Group · G1051
- Contagious Interview · G1052
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.