LiveActive security incident?Get immediate response
MITRE ATT&CK® Technique

T1083: File and Directory Discovery

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate.CitationWindows Commands JPCERT Custom tools may also be used to gather file and directory information and interact with the Native API. Adversaries may also leverage a Network Device CLI on network devices to gather file and directory information (e.g. dir, show flash, and/or nvram).CitationUS-CERT-TA18-106A

Some files and directories may require elevated or specific user permissions to access.

EnterpriseT1083TechniqueObject v1.7Modified
Glexia's Take · Automated analysis

Security context for executives and security teams

Automation confidenceMedium

File and Directory Discovery is the basic inventory step adversaries use after access to understand what data, systems, shares, device storage, or restricted paths are worth pursuing next. For leaders, its importance is not that commands like dir, ls, find, tree, show flash, or nvram are inherently malicious; it is that unusual enumeration can be an early signal of hands-on-keyboard activity, data targeting, ransomware staging, or cyber-physical reconnaissance on hosts, ESXi, network devices, and shared file locations.

Executive priority

Prioritize this technique as a coverage validation item for SOC visibility and incident scoping rather than as a standalone high-confidence alert. It matters for business continuity because broad file and directory enumeration often precedes decisions about what to steal, encrypt, or manipulate. Executives should ask whether monitoring covers servers, workstations, ESXi, Linux/macOS, Windows, network device CLI activity, and network shares, and whether responders can distinguish normal administration from suspicious recursive discovery across privilege contexts.

Technical view

ATT&CK provides no official detection text for T1083, but the relationship to DET0370, Recursive Enumeration of Files and Directories Across Privilege Contexts, gives a practical direction: validate detections for recursive or wide-scope enumeration, especially when performed by unusual users, service accounts, newly spawned shells, custom tools, or processes interacting with native APIs. Tune by platform: Windows command utilities, Linux/macOS shell utilities, ESXi shell or management activity, and network device CLI commands such as dir, show flash, and nvram. Treat findings as context-rich discovery indicators and correlate with prior access, privilege changes, credential use, network share access, and subsequent collection or exfiltration behavior.

Likely telemetry

  • Process creation and command-line telemetry for shell utilities such as dir, tree, ls, find, and locate
  • EDR or host telemetry showing recursive file system enumeration or unusual directory traversal
  • File system audit events for access to sensitive directories or network shares
  • Authentication and privilege context information for the user or process performing enumeration
  • Network share access logs where host or share discovery is in scope

Detection direction

  • Validate whether DET0370-style logic or equivalent analytics can identify recursive enumeration across different privilege contexts.
  • Baseline legitimate administrative, backup, indexing, software deployment, and troubleshooting activity to reduce false positives.
  • Correlate enumeration with suspicious parent processes, newly created shells, remote sessions, uncommon service account behavior, or access to sensitive shares.
  • Do not rely only on command names; custom tools may gather file and directory information through native APIs.
  • Confirm coverage beyond Windows endpoints, including Linux, macOS, ESXi, network devices, and shared storage where those platforms exist.

Mitigation priorities

  • Apply least-privilege access to sensitive directories, shares, device storage, and administrative interfaces so discovery is constrained by role.
  • Harden and monitor network device CLI access, including command accounting where feasible.
  • Ensure endpoint, server, ESXi, and network device logging is retained long enough to support incident reconstruction.
  • Review permissions on high-value file repositories and operational technology or SCADA-related data stores where relevant to the environment.
  • Document normal administrative enumeration patterns so SOC teams can tune detections without suppressing meaningful anomalies.
Additional notes and limits

This technique is broadly used across many ATT&CK relationships, including espionage, ransomware, supply-chain, botnet, data theft, and critical infrastructure-related campaign contexts. Its value is strongest when combined with surrounding behaviors because file and directory listing is also common in benign administration. The supplied relationship to DET0370 is the key detection anchor.

MITRE did not provide official detection guidance for this object, and the supplied fields do not include procedure-level details for each related group or campaign. Local telemetry, asset criticality, user baselines, and platform coverage are required to determine whether observed enumeration is suspicious.

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Official MITRE ATT&CK definition

File and Directory Discovery

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate.CitationWindows Commands JPCERT Custom tools may also be used to gather file and directory information and interact with the Native API. Adversaries may also leverage a Network Device CLI on network devices to gather file and directory information (e.g. dir, show flash, and/or nvram).CitationUS-CERT-TA18-106A

Some files and directories may require elevated or specific user permissions to access.

View the same entry on attack.mitre.org (MITRE-hosted reference; in-page links above use the Glexia ATT&CK library.)

Glexia analysis

How security teams should use this page

Treat this object as behavior context, not an attribution claim. Validate the related groups, software, data sources, and mitigations against official ATT&CK relationships and your own telemetry before making control-coverage decisions.

Relationship explorer

All related ATT&CK context

No relationships are available in the current normalized data for this object.

Change history

Object version and sync metadata

The fields below describe the current mirrored snapshot. When Glexia retains multiple ATT&CK source imports, you can open the table to compare the same object across releases (hashes and MITRE timestamps). For MITRE’s own release notes and roadmap, see ATT&CK resources — Updates.

ATT&CK release
19.1
Object version
1.7
Created
Modified
Raw hash
fd305376f76957ec...
Raw source

Mirrored ATT&CK source object

The raw object is retained through the mirrored ATT&CK source bundle and object hash. The raw endpoint returns the exact object from the mirrored bundle when available.

Source and licensing

Source: MITRE ATT&CK®. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation. Glexia is not affiliated with or endorsed by MITRE.