Skip to content
← LibraryTechnique entry
T1083Discovery

File and Directory Discovery

Enumerate files and directories on a compromised host — find sensitive files, SUID binaries, configs.

§ Where this technique fits

T1083 is catalogued under the Discovery tactic of the offensive-security kill-chain. It appears in 6 approved dossiers in the registry, typically at step 2.7 on average.

Authoritative reference: attack.mitre.org/techniques/T1083/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    BLE Replay
    IOT-BLE-REPLAY · Lateral Movement
    seen 1×
  2. 02
    LoRaWAN Replay / FCnt Reset
    OT-LORAWAN-REPLAY · Impact
    seen 1×
  3. 03
    SUID Binary Abuse
    L-SUID-ABUSE · Privilege Escalation
    seen 1×
  4. 04
    Unsecured Credentials
    T1552 · Credential Access
    seen 1×
  5. 05
    Valid Accounts
    T1078 · Initial Access
    seen 1×
  6. 06
    macOS Keychain Dump
    MAC-KEYCHAIN-DUMP · Credential Access
    seen 1×