Sigma Rule Library

MITRE ATT&CK technique

File and Directory Discovery detection rulesT1083

File and Directory Discovery (T1083) is a MITRE ATT&CK technique in the Discovery tactic. This page lists the 24 community-maintained Sigma detection rules in the library mapped to T1083 and its sub-techniques. Each rule includes its detection logic, log source, false positives and original YAML. These rules mainly target linux, windows, macos.

Top products

Tactic