File and Directory Discovery T1083

Tactic: Discovery

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Events covered

13 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 71 rules share fields, values, and exclusions.

Fields filtered most (62 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine28contains 22, regex_match 6, wildcard 3, ends_with 2, eq 1, match 1, starts_with 1/bin/bash, (?i)\x5c\x5c(10\.\d{1,3}\.\d{1,3}\.\d{1,3}|172\.(1[6-9]|2..., --results=verified, confluence , docker --image
EventType23eq 12, in 11exec, exec_event, ProcessRollup2, open, fork
process_name23in 12, eq 10, contains 1, starts_with 1find, egrep, grep, awk, bash
host.os.type22eq 21, in 1
event.type21eq 21start, change
Image19ends_with 17, eq 2, contains 1, is_not_null 1, starts_with 1, wildcard 1/find, /apt, /apt-get, /bin/, /bin/ls
process.args17in 8, eq 5, contains 3, starts_with 3, wildcard 3-2000, -4000, -6000, -r, -type
EventID7eq 74688, 1, 4104, 4103
event.category5eq 5, in 1process, file
ParentImage4is_not_null 2, ends_with 1, starts_with 1/dev/shm/, /home/, /root/, \explorer.exe
execve_command4in 4* .*, * ./.*, *.accdb*, *.avi*, *.db*
sourcetype4eq 4auditd
OriginalFileName3eq 3dirlister.exe, pchunter.exe, seatbelt.exe
ScriptBlockText3contains 2, eq 1, in 1-append, -erroraction , -path , -recurse, .getgporeport()
TargetFilename3eq 2, starts_with 2/etc/modprobe.conf, /etc/modprobe.d, /etc/modprobe.d/, /library/preferences/com.apple.timemachine.plist, /var/lib/kubelet/pods/

Top indicator values (842 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
211078
EventTypein
exec
11201
EventTypein
exec_event
11149
EventTypein
ProcessRollup2
9117
EventTypein
start
9163
EventTypein
executed
798
EventTypein
process_started
783
EventTypeeq
exec
10576
process_namein
grep
917
process_namein
egrep
814
process_namein
find
714
process_namein
fgrep
610
process_namein
cat
527
process_namein
locate
55
process_namein
awk
421
process_namein
bash
4202
process_namein
mlocate
44
process_namein
sed
413
process_namein
sh
4197
process_nameeq
find
510
Imageends_with
/find
45
event.categoryeq
process
4142
sourcetypeeq
auditd
458
CommandLinecontains
/bin/bash
38
CommandLinecontains
/bin/dash
37
CommandLinecontains
/bin/fish
37
CommandLinecontains
/bin/sh
312
CommandLinecontains
/bin/zsh
38
CommandLinecontains
access_key
33
CommandLinecontains
id_dsa
33

Exclusions (226 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
process.argseq
-xdev
3
process.argseq
/usr/bin/pkexec
2
CommandLinestarts_with
event0.process.command_line
2
CommandLinestarts_with
event1.process.command_line
2
ParentImagestarts_with
/var/lib/docker/
2
process.args_counteq
7
2
process.args_countge
12
2
process_namestarts_with
python
2
CommandLineends_with
/tmp/NBInstallAnswer.conf
1
CommandLineeq
find / -perm /6000 -type f -exec chmod a-s {} ;
1
CommandLineeq
find / -perm /6000 -type f -exec chmod g-s {} ;
1
CommandLinein
cat /etc/login.defs
1
CommandLinein
cat /home/asterisk/.aws/credentials
1
CommandLinein
find /etc/zerum-stacks/lynx/wdr_proxy/.htpasswd -type f
1
CommandLinein
find /run/credentials/getty@tty3.service -xdev -type f ( -perm -0002 -a !...
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 24 rules

Elastic 28 rules

Splunk 11 rules

Kusto 7 rules

Panther 1 rule