MITRE ATT&CK technique
T1083 — File and Directory Discovery
Last fetched
T1083 (File and Directory Discovery) is a MITRE ATT&CK technique tracked in WhisperGraph, serving the Discovery tactic.
Description
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Many command shell utilities can be used to obtain this information. Examples include <code>dir</code>, <code>tree</code>, <code>ls</code>, <code>find</code>, and <code>locate</code>.(Citation: Windows Commands JPCERT) Custom tools may also be used to gather file and directory information and interact with the [Native API](https://attack.mitre.org/techniques/T1106). Adversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather file and directory information (e.g. <code>dir</code>, <code>show flash</code>, and/or <code>nvram</code>).(Citation: US-CERT-TA18-106A) Some files and directories may require elevated or specific user permissions to access.
Tactics
Threat actors observed using this technique
- Aoqin Dragon
- Dragonfly
- Confucius
- Volt Typhoon
- Mustang Panda
- ToddyCat
- Play
- Contagious Interview
- Sowbug
- APT5
- APT3
- UNC3886
- Scattered Spider
- Gamaredon Group
- Leafminer
- Inception
- BRONZE BUTLER
- MirrorFace
- Ke3chang
- Fox Kitten
- Medusa Group
- menuPass
- FIN13
- ShinyHunters
- APT41
- LuminousMoth
- Turla
- MuddyWater
- Velvet Ant
- APT39
- APT38
- Sandworm Team
- APT32
- Lotus Blossom
- Magic Hound
- APT28
- Windigo
- Kimsuky
- TeamTNT
- Tropic Trooper
- APT18
- Sidewinder
- admin@338
- Winnti Group
- Darkhotel
- Winter Vivern
- Patchwork
- Dark Caracal
- Chimera
- HAFNIUM
- RedCurl
- Lazarus Group
- MUSTANG PANDA
- DarkHotel
© The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.
Related pages
Pivot from T1083 into its tactic, related techniques and the actors that use it.
Queries
Resolves the segment to this technique or tactic.
MATCH (t:ATTACK_PATTERN {name: $id})
RETURN t.id AS id, t.name AS name, t.kind AS kind, t.description AS descriptionRun yourself →The tactic(s) this technique serves.
MATCH (t:ATTACK_PATTERN {name: $id})-[:USES_TACTIC]->(tac:ATTACK_PATTERN)
RETURN tac.id AS id, tac.name AS name
LIMIT 10Run yourself →This id's parent technique, if it is a sub-technique.
MATCH (p:ATTACK_PATTERN {name: $parentId})
RETURN p.id AS id, p.name AS name
LIMIT 1Run yourself →Sub-techniques of this technique, if any.
MATCH (c:ATTACK_PATTERN) WHERE c.id STARTS WITH $subPrefix
RETURN c.id AS id, c.name AS name
ORDER BY c.id
LIMIT 25Run yourself →Threat actors observed using this technique.
MATCH (a:ACTOR)-[:USES_TECHNIQUE]->(t:ATTACK_PATTERN {name: $id})
RETURN a.name AS name
LIMIT 100Run yourself →Or query Whisper from your own LLM workflow via the Whisper MCP server.