Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1083

T1083File and Directory Discovery

T1083 — File and Directory Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 27 detection use cases covering it and 26 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
27Use cases
26Articles
0Sub-techniques
1Tactic

Use cases covering this technique (27)

Linux Auditd Database File And Directory Discovery ESCU actions · hunting P Linux Auditd File And Directory Discovery ESCU actions · hunting P Linux Auditd Hidden Files And Directories Creation ESCU actions · hunting P Linux Auditd Virtual Disk File And Directory Discovery ESCU actions · hunting P [LLM] Non-forensic process bulk-reading the App.MenuItem Biome stream Bespoke actions · hunting DSΣPDDCS [LLM] AI coding agent descendant reading developer credentials / env (Agentjacking credential access) Bespoke actions · hunting DSΣPDDCS [LLM] Web-facing exposure of dev.env / .env config file (returns 200) Bespoke recon · alerting DSΣPDDCSCW [LLM] Stata-authored log file written with shell metacharacters or path traversal in filename (CVE-2026-47708) Bespoke exploit · alerting DSΣPDDCS [LLM] Path-traversal exploit hitting Vitest /__vitest_attachment__ endpoint (CVE-2026-47429 PoC) Bespoke exploit · alerting DSΣPDDCS [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] FileBrowser Quantum public share PATCH path traversal in fromPath/toPath (GHSA-qqqm-5547-774x) Bespoke exploit · alerting SPDD [LLM] Megalodon harvester: bash secret-grep across workspace (API_KEY|SECRET|TOKEN|PRIVATE_KEY|BEGIN RSA) Bespoke actions · hunting DSΣPDDCS [LLM] OCI image extraction creates symlink with absolute path target (CWE-61 primitive) Bespoke exploit · alerting DSΣPDDCS [LLM] Fission Function Name Enumeration via /fission-function/ Probing (CVE-2026-46614 recon) Bespoke recon · hunting SPDD [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) Bespoke actions · hunting DSPDDCS [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) Bespoke actions · hunting DSPDDCS [LLM] Node.js process bulk-reading cloud & SCM credential files in single session Bespoke actions · hunting DSPDDCS [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths Bespoke actions · hunting DSPDDCS [LLM] Node.js postinstall reading .env / .env.* during package install Bespoke actions · alerting DSPDDCS [LLM] AI CLI weaponized for recon — claude/gemini/q invoked under npm install lineage Bespoke actions · alerting DSΣPDDCS [LLM] AI CLI tool (claude/gemini/q) spawned non-interactively by node/npm/npx for recon Bespoke actions · alerting DSΣPDDCS [LLM] TruffleHog secret-scanner execution on developer / CI host (SHA1-Hulud credential harvest) Bespoke actions · alerting DSΣPDDCS [LLM] TruffleHog secret-scanner executed by node/npm postinstall context Bespoke actions · alerting DSΣPDDCS [LLM] Postinstall node child enumerating multiple developer credential stores Bespoke actions · hunting DSPDDCS [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity inventory file written to /tmp (inventory.txt / inventory.txt.bak) Bespoke actions · alerting DSΣPDDCS [LLM] Container PID 1 environment harvest via /proc/1/environ read Bespoke actions · hunting DSΣPDDCS

Articles citing this technique (26)