T1083File and Directory Discovery
T1083 — File and Directory Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 35 detection use cases covering it and 29 threat-intel articles citing it.
Discovery
35Use cases
29Articles
0Sub-techniques
1Tactic
Use cases covering this technique (35)
Splunk Path Traversal In Splunk App For Lookup File Edit Linux Auditd Database File And Directory Discovery Linux Auditd File And Directory Discovery Linux Auditd Hidden Files And Directories Creation Linux Auditd Virtual Disk File And Directory Discovery Path traversal SPL injection Splunk Absolute Path Traversal Using runshellscript Splunk Unauthenticated Path Traversal Modules Messaging [LLM] Rails/libvips worker reading process environment or system secrets (CVE-2026-66066 file-read) [LLM] AppVShNotify.exe spawning child processes (NightLedger command dispatcher execution) [LLM] n8n/Node child command accessing N8N_ENCRYPTION_KEY or host credential stores [LLM] Windchill filesystem-enumeration artifact flst.txt written by web tier (CVE-2026-12569 discovery) [LLM] LinPEAS / SUID sweep privilege-escalation enumeration on Linux [LLM] EnvoyExtensionPolicy Lua with double-slash path traversal to secrets (CVE-2026-53713) [LLM] HelloExecutor recon enumerating ViPNet Client/Administrator Export key stores [LLM] EGroupware CVE-2026-27823 arbitrary file read via importexport download path traversal [LLM] LaunchServer path-traversal exploit signature: request-target without leading slash / %2e%2e on port 9274 [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) [LLM] Megalodon harvester: bash secret-grep across workspace (API_KEY|SECRET|TOKEN|PRIVATE_KEY|BEGIN RSA) [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) [LLM] Node.js process bulk-reading cloud & SCM credential files in single session [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths [LLM] Node.js postinstall reading .env / .env.* during package install [LLM] TruffleHog secret-scanner execution on developer / CI host (SHA1-Hulud credential harvest) [LLM] TruffleHog secret-scanner executed by node/npm postinstall context [LLM] Postinstall node child enumerating multiple developer credential stores [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags [LLM] Nx s1ngularity inventory file written to /tmp (inventory.txt / inventory.txt.bak) [LLM] Container PID 1 environment harvest via /proc/1/environ read [LLM] URL-encoded directory traversal (%2e%2e) against node 'st' static-file route (CVE-2014-3744) [LLM] Spring4Shell post-exploitation arbitrary file read (/etc/passwd via relocated docBase) [LLM] Web path-traversal arbitrary file read via '../' in static-file URL (Crow CVE-2021-23514) [LLM] URL-encoded directory traversal (%2e%2e) against Node 'st' static file server [LLM] Successful sensitive-file disclosure via st traversal (/etc/passwd, package-lock.json)Articles citing this technique (29)
crit Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads art-06
crit Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE art-75