T1083 File and Directory Discovery
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Turla Group Lateral Movementcriticaltest · windows
- WannaCry Ransomware Activitycriticaltest · windows
- HackTool - PCHunter Executionhightest · windows
- PUA - Seatbelt Executionhightest · windows
- Shell Execution GCC - Linuxhightest · linux
- Shell Execution via Find - Linuxhightest · linux
- Shell Execution via Flock - Linuxhightest · linux
- Shell Execution via Nice - Linuxhightest · linux
- Vim GTFOBin Abuse - Linuxhightest · linux
- Potential Discovery Activity Using Find - Linuxmediumtest · linux
- Potential Discovery Activity Using Find - MacOSmediumtest · macos
- Powershell Directory Enumerationmediumtest · windows
- Powershell Sensitive File Discoverymediumtest · windows
- Shell Invocation via Apt - Linuxmediumtest · linux
- Source Code Enumeration Detection by Keywordmediumtest · webserver
- PUA - TruffleHog Executionmediumexperimental · windows
- PUA - TruffleHog Execution - Linuxmediumexperimental · linux
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.