MITRE ATT&CK CoA - T1083 - File and Directory Discovery

This playbook Remediates the File and Directory Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. ***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Techniques Handled: - T1083: File and Directory Discovery Kill Chain phases: - Discovery MITRE ATT&CK Description: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate. Custom tools may also be used to gather file and directory information and interact with the Native API. Possible playbook uses: - The playbook can be used independently to handle and remediate the specific technique. - The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

MITRE ATT&CK - Courses of Action · 8 tasks · 0 inputs · 1 output

Details

IDMITRE ATT&CK CoA - T1083 - File and Directory Discovery
From Version6.5.0
Tasks8

README

This playbook Remediates the File and Directory Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.

***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:

  • T1083: File and Directory Discovery

Kill Chain phases:

  • Discovery

MITRE ATT&CK Description:

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate. Custom tools may also be used to gather file and directory information and interact with the Native API.

Possible playbook uses:

  • The playbook can be used independently to handle and remediate the specific technique.
  • The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
  • The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

This playbook does not use any sub-playbooks.

Integrations

This playbook does not use any integrations.

Scripts

  • SetGridField
  • IsIntegrationAvailable
  • Set

Commands

This playbook does not use any commands.

Playbook Inputs


There are no inputs for this playbook.

Playbook Outputs


Path Description Type
Handled.Techniques The techniques handled in this playbook unknown

Playbook Image


MITRE ATT&CK CoA - T1083 - File and Directory Discovery

Outputs

  • Handled.Techniques — The techniques handled in this playbook

Flowchart

yes Start Start Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors Cortex XDR monitors for b... Done Done Is Cortex XDR integration Enabled? Is Cortex XDR integration... Manual - Enable Cortex XDR integration Manual - Enable Cortex XD... Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors Cortex XDR monitors for b... Set technique handled Set technique handled Set grid field Set grid field
description: "This playbook Remediates the File and Directory Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.\n \n***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\nTechniques Handled:\n- T1083: File and Directory Discovery\n\nKill Chain phases:\n- Discovery\n\nMITRE ATT&CK Description:\n\nAdversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nMany command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate.  Custom tools may also be used to gather file and directory information and interact with the Native API.\n\nPossible playbook uses:\n- The playbook can be used independently to handle and remediate the specific technique.\n- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input."
id: MITRE ATT&CK CoA - T1083 - File and Directory Discovery
inputs: []
name: MITRE ATT&CK CoA - T1083 - File and Directory Discovery
outputs:
- contextPath: Handled.Techniques
  description: The techniques handled in this playbook
  type: unknown
starttaskid: "0"
tasks:
  "0":
    id: "0"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "5"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 8e60441a-86eb-4c0b-84f4-3bde2619a537
      iscommand: false
      name: ""
      version: -1
      description: ''
    taskid: 8e60441a-86eb-4c0b-84f4-3bde2619a537
    timertriggers: []
    type: start
    view: |-
      {
        "position": {
          "x": 265,
          "y": -110
        }
      }
  "1":
    id: "1"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "6"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors.
      id: 3f6e55d4-9036-473a-8222-d175d8303d44
      iscommand: false
      name: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors
      type: regular
      version: -1
    taskid: 3f6e55d4-9036-473a-8222-d175d8303d44
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 265,
          "y": 540
        }
      }
  "2":
    id: "2"
    ignoreworker: false
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: f0044a7f-a9ba-485e-8dc7-6f5589920c0a
      iscommand: false
      name: Done
      type: title
      version: -1
      description: ''
    taskid: f0044a7f-a9ba-485e-8dc7-6f5589920c0a
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 265,
          "y": 1090
        }
      }
  "3":
    id: "3"
    ignoreworker: false
    nexttasks:
      '#default#':
      - "4"
      "yes":
      - "1"
    note: false
    quietmode: 0
    scriptarguments:
      brandname:
        simple: Cortex XDR - IR
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Returns 'yes' if integration brand is available. Otherwise returns 'no'
      id: 423e30aa-9b91-422d-8e78-625a86b54b17
      iscommand: false
      name: Is Cortex XDR integration Enabled?
      script: IsIntegrationAvailable
      type: condition
      version: -1
    taskid: 423e30aa-9b91-422d-8e78-625a86b54b17
    timertriggers: []
    type: condition
    view: |-
      {
        "position": {
          "x": 265,
          "y": 195
        }
      }
  "4":
    id: "4"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "1"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: |
        Enable the Cortex XDR integration to follow this CoA.

        If needed - please contact your Palo Alto Networks account manager for future guidance and assistance.
      id: 41184bd3-4ea5-4c0f-8990-f6b1bcaf2edc
      iscommand: false
      name: Manual - Enable Cortex XDR integration
      type: regular
      version: -1
    taskid: 41184bd3-4ea5-4c0f-8990-f6b1bcaf2edc
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 520,
          "y": 370
        }
      }
  "5":
    id: "5"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "3"
    note: false
    quietmode: 0
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      id: 582019ae-12f5-4b29-823b-a79ef3543d00
      iscommand: false
      name: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors
      type: title
      version: -1
      description: ''
    taskid: 582019ae-12f5-4b29-823b-a79ef3543d00
    timertriggers: []
    type: title
    view: |-
      {
        "position": {
          "x": 265,
          "y": 50
        }
      }
  "6":
    id: "6"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "7"
    note: false
    quietmode: 0
    scriptarguments:
      append:
        simple: "true"
      key:
        simple: Handled.Techniques
      stringify: {}
      value:
        simple: T1083
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Set a value in context under the key you entered.
      id: 27993e33-d2f9-48bc-83bb-fa66d7382af7
      iscommand: false
      name: Set technique handled
      script: Set
      type: regular
      version: -1
    taskid: 27993e33-d2f9-48bc-83bb-fa66d7382af7
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 265,
          "y": 720
        }
      }
  "7":
    continueonerror: true
    id: "7"
    ignoreworker: false
    nexttasks:
      '#none#':
      - "2"
    note: false
    quietmode: 0
    scriptarguments:
      columns:
        simple: technique
      context_path:
        simple: Handled.Techniques
      grid_id:
        simple: handledtechniques
      keys: {}
      overwrite: {}
      sort_by: {}
      unpack_nested_elements: {}
    separatecontext: false
    skipunavailable: false
    task:
      brand: ""
      description: Creates a Grid table from items or key-value pairs.
      id: 1583d9e0-c780-4d30-8040-58036211ef81
      iscommand: false
      name: Set grid field
      script: SetGridField
      type: regular
      version: -1
    taskid: 1583d9e0-c780-4d30-8040-58036211ef81
    timertriggers: []
    type: regular
    view: |-
      {
        "position": {
          "x": 265,
          "y": 900
        }
      }
version: -1
view: |-
  {
    "linkLabelsPosition": {
      "3_1_yes": 0.41
    },
    "paper": {
      "dimensions": {
        "height": 1265,
        "width": 635,
        "x": 265,
        "y": -110
      }
    }
  }
tests:
- No tests (auto formatted)
fromversion: 6.5.0