Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1083

T1083File and Directory Discovery

T1083 — File and Directory Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 35 detection use cases covering it and 29 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
35Use cases
29Articles
0Sub-techniques
1Tactic

Use cases covering this technique (35)

Splunk Path Traversal In Splunk App For Lookup File Edit ESCU actions · hunting P Linux Auditd Database File And Directory Discovery ESCU actions · hunting P Linux Auditd File And Directory Discovery ESCU actions · hunting P Linux Auditd Hidden Files And Directories Creation ESCU actions · hunting P Linux Auditd Virtual Disk File And Directory Discovery ESCU actions · hunting P Path traversal SPL injection ESCU actions · alerting P Splunk Absolute Path Traversal Using runshellscript ESCU actions · hunting P Splunk Unauthenticated Path Traversal Modules Messaging ESCU actions · hunting P [LLM] Rails/libvips worker reading process environment or system secrets (CVE-2026-66066 file-read) Bespoke actions · alerting SΣPCS [LLM] AppVShNotify.exe spawning child processes (NightLedger command dispatcher execution) Bespoke exploit · alerting DSΣPDDCS [LLM] n8n/Node child command accessing N8N_ENCRYPTION_KEY or host credential stores Bespoke actions · alerting DSΣPDDCS [LLM] Windchill filesystem-enumeration artifact flst.txt written by web tier (CVE-2026-12569 discovery) Bespoke actions · hunting DSΣPDDCS [LLM] LinPEAS / SUID sweep privilege-escalation enumeration on Linux Bespoke exploit · hunting DSΣPDDCS [LLM] EnvoyExtensionPolicy Lua with double-slash path traversal to secrets (CVE-2026-53713) Bespoke exploit · alerting SΣPDD [LLM] HelloExecutor recon enumerating ViPNet Client/Administrator Export key stores Bespoke recon · hunting DSΣPDDCS [LLM] EGroupware CVE-2026-27823 arbitrary file read via importexport download path traversal Bespoke exploit · alerting SΣP [LLM] LaunchServer path-traversal exploit signature: request-target without leading slash / %2e%2e on port 9274 Bespoke exploit · alerting DSΣPCS [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] Megalodon harvester: bash secret-grep across workspace (API_KEY|SECRET|TOKEN|PRIVATE_KEY|BEGIN RSA) Bespoke actions · hunting DSΣPDDCS [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) Bespoke actions · hunting DSPDDCS [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) Bespoke actions · hunting DSPDDCS [LLM] Node.js process bulk-reading cloud & SCM credential files in single session Bespoke actions · hunting DSPDDCS [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths Bespoke actions · hunting DSPDDCS [LLM] Node.js postinstall reading .env / .env.* during package install Bespoke actions · alerting DSPDDCS [LLM] TruffleHog secret-scanner execution on developer / CI host (SHA1-Hulud credential harvest) Bespoke actions · alerting DSΣPDDCS [LLM] TruffleHog secret-scanner executed by node/npm postinstall context Bespoke actions · alerting DSΣPDDCS [LLM] Postinstall node child enumerating multiple developer credential stores Bespoke actions · hunting DSPDDCS [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity inventory file written to /tmp (inventory.txt / inventory.txt.bak) Bespoke actions · alerting DSΣPDDCS [LLM] Container PID 1 environment harvest via /proc/1/environ read Bespoke actions · hunting DSΣPDDCS [LLM] URL-encoded directory traversal (%2e%2e) against node 'st' static-file route (CVE-2014-3744) Bespoke exploit · hunting SΣP [LLM] Spring4Shell post-exploitation arbitrary file read (/etc/passwd via relocated docBase) Bespoke actions · alerting SΣPCS [LLM] Web path-traversal arbitrary file read via '../' in static-file URL (Crow CVE-2021-23514) Bespoke exploit · alerting SΣP [LLM] URL-encoded directory traversal (%2e%2e) against Node 'st' static file server Bespoke exploit · hunting SΣP [LLM] Successful sensitive-file disclosure via st traversal (/etc/passwd, package-lock.json) Bespoke actions · alerting SΣP

Articles citing this technique (29)