File and Directory Discovery T1083

Tactic: Discovery

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Events covered

13 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 71 rules share fields, values, and exclusions.

Fields filtered most (62 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine28contains 22, regex_match 6, wildcard 3, ends_with 2, eq 1, match 1, starts_with 1/bin/bash, (?i)\x5c\x5c(10\.\d{1,3}\.\d{1,3}\.\d{1,3}|172\.(1[6-9]|2..., --results=verified, confluence , docker --image
EventType23eq 12, in 11exec, exec_event, ProcessRollup2, open, fork
process_name23in 12, eq 10, contains 1, starts_with 1find, egrep, grep, awk, bash
host.os.type22eq 21, in 1
event.type21eq 21start, change
Image19ends_with 17, eq 2, contains 1, is_not_null 1, starts_with 1, wildcard 1/find, /apt, /apt-get, /bin/, /bin/ls
process.args17in 8, eq 5, contains 3, starts_with 3, wildcard 3-2000, -4000, -6000, -r, -type
EventID7eq 74688, 1, 4104, 4103
event.category5eq 5, in 1process, file
ParentImage4is_not_null 2, ends_with 1, starts_with 1/dev/shm/, /home/, /root/, \explorer.exe
execve_command4in 4* .*, * ./.*, *.accdb*, *.avi*, *.db*
sourcetype4eq 4auditd
OriginalFileName3eq 3dirlister.exe, pchunter.exe, seatbelt.exe
ScriptBlockText3contains 2, eq 1, in 1-append, -erroraction , -path , -recurse, .getgporeport()
TargetFilename3eq 2, starts_with 2/etc/modprobe.conf, /etc/modprobe.d, /etc/modprobe.d/, /library/preferences/com.apple.timemachine.plist, /var/lib/kubelet/pods/

Top indicator values (842 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
211087
EventTypein
exec
11206
EventTypein
exec_event
11150
EventTypein
ProcessRollup2
9118
EventTypein
start
9168
EventTypein
executed
798
EventTypein
process_started
783
EventTypeeq
exec
10579
process_namein
grep
918
process_namein
egrep
814
process_namein
find
715
process_namein
fgrep
611
process_namein
cat
528
process_namein
locate
55
process_namein
awk
422
process_namein
bash
4202
process_namein
mlocate
44
process_namein
sed
414
process_namein
sh
4197
process_nameeq
find
510
Imageends_with
/find
45
event.categoryeq
process
4141
sourcetypeeq
auditd
458
CommandLinecontains
/bin/bash
38
CommandLinecontains
/bin/dash
37
CommandLinecontains
/bin/fish
37
CommandLinecontains
/bin/sh
312
CommandLinecontains
/bin/zsh
38
CommandLinecontains
access_key
33
CommandLinecontains
id_dsa
33

Exclusions (227 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.argseq
-xdev
3
process.argseq
/usr/bin/pkexec
2
CommandLinestarts_with
event0.process.command_line
2
CommandLinestarts_with
event1.process.command_line
2
ParentImagestarts_with
/var/lib/docker/
2
process.args_counteq
7
2
process.args_countge
12
2
process_namestarts_with
python
2
CommandLineends_with
/tmp/NBInstallAnswer.conf
1
CommandLineeq
find / -perm /6000 -type f -exec chmod a-s {} ;
1
CommandLineeq
find / -perm /6000 -type f -exec chmod g-s {} ;
1
CommandLinein
cat /etc/login.defs
1
CommandLinein
cat /home/asterisk/.aws/credentials
1
CommandLinein
find /etc/zerum-stacks/lynx/wdr_proxy/.htpasswd -type f
1
CommandLinein
find /run/credentials/getty@tty3.service -xdev -type f ( -perm -0002 -a !...
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 24 rules

Elastic 28 rules

Splunk 11 rules

Kusto 7 rules

Panther 1 rule