Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1083

T1083File and Directory Discovery

T1083 — File and Directory Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 28 detection use cases covering it and 22 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
28Use cases
22Articles
0Sub-techniques
1Tactic

Use cases covering this technique (28)

Linux Auditd Database File And Directory Discovery ESCU actions · hunting P Linux Auditd File And Directory Discovery ESCU actions · hunting P Linux Auditd Hidden Files And Directories Creation ESCU actions · hunting P Linux Auditd Virtual Disk File And Directory Discovery ESCU actions · hunting P Path traversal SPL injection ESCU actions · alerting P Splunk Absolute Path Traversal Using runshellscript ESCU actions · hunting P Splunk Path Traversal In Splunk App For Lookup File Edit ESCU actions · hunting P Splunk Unauthenticated Path Traversal Modules Messaging ESCU actions · hunting P [LLM] PTC Windchill Java/Tomcat process spawning shell or flst.txt recon Bespoke exploit · alerting DSΣPDDCS [LLM] EnvoyExtensionPolicy Lua with double-slash path traversal to secrets (CVE-2026-53713) Bespoke exploit · alerting SΣPDD [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] Megalodon harvester: bash secret-grep across workspace (API_KEY|SECRET|TOKEN|PRIVATE_KEY|BEGIN RSA) Bespoke actions · hunting DSΣPDDCS [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) Bespoke actions · hunting DSPDDCS [LLM] Burst credential-file harvest by VS Code / node process (Nx Console stealer behaviour) Bespoke actions · hunting DSPDDCS [LLM] Node.js process bulk-reading cloud & SCM credential files in single session Bespoke actions · hunting DSPDDCS [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths Bespoke actions · hunting DSPDDCS [LLM] Node.js postinstall reading .env / .env.* during package install Bespoke actions · alerting DSPDDCS [LLM] TruffleHog secret-scanner execution on developer / CI host (SHA1-Hulud credential harvest) Bespoke actions · alerting DSΣPDDCS [LLM] TruffleHog secret-scanner executed by node/npm postinstall context Bespoke actions · alerting DSΣPDDCS [LLM] Postinstall node child enumerating multiple developer credential stores Bespoke actions · hunting DSPDDCS [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity inventory file written to /tmp (inventory.txt / inventory.txt.bak) Bespoke actions · alerting DSΣPDDCS [LLM] Container PID 1 environment harvest via /proc/1/environ read Bespoke actions · hunting DSΣPDDCS [LLM] URL-encoded directory traversal (%2e%2e) against node 'st' static-file route (CVE-2014-3744) Bespoke exploit · hunting SΣP [LLM] Spring4Shell post-exploitation arbitrary file read (/etc/passwd via relocated docBase) Bespoke actions · alerting SΣPCS [LLM] Web path-traversal arbitrary file read via '../' in static-file URL (Crow CVE-2021-23514) Bespoke exploit · alerting SΣP [LLM] URL-encoded directory traversal (%2e%2e) against Node 'st' static file server Bespoke exploit · hunting SΣP [LLM] Successful sensitive-file disclosure via st traversal (/etc/passwd, package-lock.json) Bespoke actions · alerting SΣP

Articles citing this technique (22)