FORENSIA

ATT&CK · T1083

File and Directory Discovery

Tactics: discovery

About

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Many command shell utilities can be used to obtain this information. Examples include <code>dir</code>, <code>tree</code>, <code>ls</code>, <code>find</code>, and <code>locate</code>. Custom tools may also be used to gather file and directory information and interact with the Native API. Adversaries may also leverage a Network Device CLI on network devices to gather file and directory information (e.g. <code>dir</code>, <code>show flash</code>, and/or <code>nvram</code>). Some files and directories may require elevated or specific user permissions to access.

Platforms: ESXi, Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗

Used by actors

51 known groups

Software

305 malware/tools implement this

TaidoorPlugXIxesheChina ChopperDerusbiUroburosCHOPSTICKBACKSPACENETEAGLESPACESHIPFLASHFLOODADVSTORESHELLPinchDukeGeminiDukeCosmicDukeMiniDukeRARSTONEWinMMDustySkySHOTPUTELMER4H RAT3PARA RATBLACKCOFFEEHTTPBrowserOwaAuthPsyloMobileOrderEliseMisdatZLibKasidetBlackEnergyRoverEpicBackdoor.OldreaTrojan.KaraganycmdPrikormkaCrimsonPisloaderRemsecBBSRATBADNEWSAutoIt backdoorTINYTYPHONUSBStealerPowerDukeWinnti for WindowsStreamExChChesPteranodonRTMMoonWindRedLeavesCobalt StrikeSOUNDBITEXAgentOSXVolgmerFALLCHILLFinFisherPOWRUNERPupyForfilesNETWIREJPINHydraqPasamLinfoCORALDECKPOORAIMWINERACKSmoke LoaderOrzBandookCrossRATKwampirsGravityRATProxysvcBankshotROKRATSynAckytyGold DragonKoadicZebrocyBrave PrinceDDKONGInnaputRATInvisiMoleTYPEFRAMEKazuarTrickBotBisonalKEYMARBLENDiskMonitorUPPERCUTFruitFlyjRATZeus PandaRemcosBadPatchMicropsiaOctopusAzorultSeasaltOceanSaltAuditCredCardinal RATzwShellCannonDenisKONNIEmpireWannaCryNotPetyaRemexiHOPLIGHTPoshC2njRATKeyBoyOSX/ShlayerMacheteFysbisZxShellBabySharkPoetRATHotCroissantImminent MonitorPLEADTSCookieKivarsAttorOkrumMESSAGETAPShimRatRyukLokibotRising SunUSBferryMetamorfoAria-bodyRamsaySDBbotWindTailTajMahalSkidmapdown_newAvengerBackConfigCrackMapExecStrongPityCookieMinerGoldenSpyREvilDaclsCryptoisticFatDukeSoreFangBLINDINGCANKGH_SPYSLOTHFULMEDIABazarDropBookSUNBURSTSUNSPOTBlackMouldDtrackCaterpillar WebShellContiMegaCortexLookBackTAINTEDSCRIBEPenquinRemoteUtilitiesP.A.S. WebshellKinsingDokiStuxnetIndustroyerKillDiskSideTwistClopWastedLockerSombRATDEATHRANSOMFIVEHANDSAppleSeedSiloscapeCubaFYAntiRainyDayNebulaeGrimAgentSliverBoomBoxBabukAvaddonBADFLICKPeppyObliqueRATTurianQakBotBoxCaonMarkiRATBLUELIGHTXCSSETDiavolClamblingFoggyWebSysUpdateThreatNeedleGelsemiumWarzoneRATZoxDarkWatchmanCharmPowerQuietSieveCyclops BlinkWhisperGateSILENTTRINITYCaddyWiperHermeticWiperMacMaOutSteelSaint BotIceAppleCreepyDriveAmadeyHeyoka BackdoorAction RATPingPullStrifeWaterRcloneSUGARDUMPccf32FunnyDreamAvosLockerPrestigemetaMainMafaldaWoody RATBlackCatBlack BastaRoyalSharpDiscoNightClubCheerscryptSamuraiNinjaLoFiSePcexterCOATHANGERPACEMAKERDarkGateZIPLINELITTLELAMB.WOOLTEAMispaduAcidRainAkiraRaspberry RobinMultiLayer WiperINC RansomwareSpicaLunarWebLunarMailRaccoon StealerCHIMNEYSWEEPROADSWEEPCuckoo StealerManjusakaDUSTTRAPLatrodectusPlaycryptAcidPourMangoODAgentExbyteBOLDMOVELightSpyMegazordAkira _v2Troll StealerGomirLockBit 2.0StealBitLockBit 3.0RansomHubHavocSplatCloakQilinMedusa RansomwareInvisibleFerretBeaverTailEmbargoDiskpartTruffleHogBRICKSTORMLODEINFOANELLDRSameCoinAshTagLAMEHUGDynoWiperLazyWiper

Corpus indicators tagged with this technique

1,791 indicators in the corpus carry T1083.

IndicatorTypeFamilySevSrc
cve-2025-34117cve851
cve-2026-5815cve851
cve-2014-2321cve851
cve-2025-2492cve852
cve-2026-3844cve851
cve-2025-34037cve851
cve-2013-3307cve852
cve-2018-8007cve851
cve-2021-4045cve851
cve-2020-22658cve852
cve-2021-25646cve851
cve-2026-0740cve851
cve-2025-7443cve851
cve-2017-17215cve852
cve-2021-27076cve851
cve-2016-5681cve852
cve-2025-11837cve852
cve-2024-1781cve851
cve-2023-44976cveransomware852
cve-2022-47945cve851
cve-2020-17456cve851
cve-2020-22653cve852
cve-2017-18377cve851
cve-2013-7471cve851
cve-2021-29441cve851
cve-2026-1969cve851
cve-2025-12057cve851
cve-2025-34085cve851
cve-2025-7852cve851
cve-2007-5693cve851

Showing the top 30 by severity of 1,791.