MITRE ATT&CK Technique
T1083File and Directory Discovery
- First Reported
- Jul 16, 2026
- Latest Reported
- Sep 17, 2026
Official Description
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from [File and Directory Discovery](https://attack.mitre.org/techniques/T1083) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Many command shell utilities can be used to obtain this information. Examples include <code>dir</code>, <code>tree</code>, <code>ls</code>, <code>find</code>, and <code>locate</code>.(Citation: Windows Commands JPCERT) Custom tools may also be used to gather file and directory information and interact with the [Native API](https://attack.mitre.org/techniques/T1106). Adversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather file and directory information (e.g. <code>dir</code>, <code>show flash</code>, and/or <code>nvram</code>).(Citation: US-CERT-TA18-106A)
Some files and directories may require elevated or specific user permissions to access.
Many command shell utilities can be used to obtain this information. Examples include <code>dir</code>, <code>tree</code>, <code>ls</code>, <code>find</code>, and <code>locate</code>.(Citation: Windows Commands JPCERT) Custom tools may also be used to gather file and directory information and interact with the [Native API](https://attack.mitre.org/techniques/T1106). Adversaries may also leverage a [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) on network devices to gather file and directory information (e.g. <code>dir</code>, <code>show flash</code>, and/or <code>nvram</code>).(Citation: US-CERT-TA18-106A)
Some files and directories may require elevated or specific user permissions to access.
- Tactics
- Discovery
- Platforms
- ESXi, Linux, macOS, Network Devices, Windows
- MITRE Version
- 1.7
- Last Modified
- May 12, 2026
Reported Context (3)
- SparroWocky can enumerate directory contents and files on mapped drives. ESET details FamousSparrow’s SparroWocky backdoor targeting Latin American governments
- A backdoor command lists directories and drives. Possible Pakistan-Linked Backdoor Targets Afghanistan
- C2 commands can list directories and enumerate the root directory. Analysis of a Low-Detection Linux Implant With Hands-On Intrusion Capabilities
Malware (2)
Threat Actors (3)
MITRE ATT&CK (43)
Vendors (3)
Products (3)
Tools (8)
Industries (4)
Countries (11)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.