MITRE ATT&CK CoA - T1083 - File and Directory Discovery
This playbook Remediates the File and Directory Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team. ***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs). Techniques Handled: - T1083: File and Directory Discovery Kill Chain phases: - Discovery MITRE ATT&CK Description: Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate. Custom tools may also be used to gather file and directory information and interact with the Native API. Possible playbook uses: - The playbook can be used independently to handle and remediate the specific technique. - The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase. - The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
MITRE ATT&CK - Courses of Action · 8 tasks · 0 inputs · 1 output
Details
| ID | MITRE ATT&CK CoA - T1083 - File and Directory Discovery |
|---|---|
| From Version | 6.5.0 |
| Tasks | 8 |
README
This playbook Remediates the File and Directory Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.
***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).
Techniques Handled:
- T1083: File and Directory Discovery
Kill Chain phases:
- Discovery
MITRE ATT&CK Description:
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Many command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate. Custom tools may also be used to gather file and directory information and interact with the Native API.
Possible playbook uses:
- The playbook can be used independently to handle and remediate the specific technique.
- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.
- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input.
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
This playbook does not use any sub-playbooks.
Integrations
This playbook does not use any integrations.
Scripts
- SetGridField
- IsIntegrationAvailable
- Set
Commands
This playbook does not use any commands.
Playbook Inputs
There are no inputs for this playbook.
Playbook Outputs
| Path | Description | Type |
|---|---|---|
| Handled.Techniques | The techniques handled in this playbook | unknown |
Playbook Image

Outputs
Handled.Techniques— The techniques handled in this playbook
Flowchart
description: "This playbook Remediates the File and Directory Discovery technique using intelligence-driven Courses of Action (COA) defined by Palo Alto Networks Unit 42 team.\n \n***Disclaimer: This playbook does not simulate an attack using the specified technique, but follows the steps to remediation as defined by Palo Alto Networks Unit 42 team’s Actionable Threat Objects and Mitigations (ATOMs).\nTechniques Handled:\n- T1083: File and Directory Discovery\n\nKill Chain phases:\n- Discovery\n\nMITRE ATT&CK Description:\n\nAdversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system. Adversaries may use the information from File and Directory Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.\n\nMany command shell utilities can be used to obtain this information. Examples include dir, tree, ls, find, and locate. Custom tools may also be used to gather file and directory information and interact with the Native API.\n\nPossible playbook uses:\n- The playbook can be used independently to handle and remediate the specific technique.\n- The playbook can be used as a part of the “Courses of Action - Defense Evasion” playbook to remediate techniques based on the kill chain phase.\n- The playbook can be used as a part of the “MITRE ATT&CK - Courses of Action” playbook, which can be triggered by different sources and accepts the technique MITRE ATT&CK ID as an input." id: MITRE ATT&CK CoA - T1083 - File and Directory Discovery inputs: [] name: MITRE ATT&CK CoA - T1083 - File and Directory Discovery outputs: - contextPath: Handled.Techniques description: The techniques handled in this playbook type: unknown starttaskid: "0" tasks: "0": id: "0" ignoreworker: false nexttasks: '#none#': - "5" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 8e60441a-86eb-4c0b-84f4-3bde2619a537 iscommand: false name: "" version: -1 description: '' taskid: 8e60441a-86eb-4c0b-84f4-3bde2619a537 timertriggers: [] type: start view: |- { "position": { "x": 265, "y": -110 } } "1": id: "1" ignoreworker: false nexttasks: '#none#': - "6" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" description: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors. id: 3f6e55d4-9036-473a-8222-d175d8303d44 iscommand: false name: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors type: regular version: -1 taskid: 3f6e55d4-9036-473a-8222-d175d8303d44 timertriggers: [] type: regular view: |- { "position": { "x": 265, "y": 540 } } "2": id: "2" ignoreworker: false note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: f0044a7f-a9ba-485e-8dc7-6f5589920c0a iscommand: false name: Done type: title version: -1 description: '' taskid: f0044a7f-a9ba-485e-8dc7-6f5589920c0a timertriggers: [] type: title view: |- { "position": { "x": 265, "y": 1090 } } "3": id: "3" ignoreworker: false nexttasks: '#default#': - "4" "yes": - "1" note: false quietmode: 0 scriptarguments: brandname: simple: Cortex XDR - IR separatecontext: false skipunavailable: false task: brand: "" description: Returns 'yes' if integration brand is available. Otherwise returns 'no' id: 423e30aa-9b91-422d-8e78-625a86b54b17 iscommand: false name: Is Cortex XDR integration Enabled? script: IsIntegrationAvailable type: condition version: -1 taskid: 423e30aa-9b91-422d-8e78-625a86b54b17 timertriggers: [] type: condition view: |- { "position": { "x": 265, "y": 195 } } "4": id: "4" ignoreworker: false nexttasks: '#none#': - "1" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" description: | Enable the Cortex XDR integration to follow this CoA. If needed - please contact your Palo Alto Networks account manager for future guidance and assistance. id: 41184bd3-4ea5-4c0f-8990-f6b1bcaf2edc iscommand: false name: Manual - Enable Cortex XDR integration type: regular version: -1 taskid: 41184bd3-4ea5-4c0f-8990-f6b1bcaf2edc timertriggers: [] type: regular view: |- { "position": { "x": 520, "y": 370 } } "5": id: "5" ignoreworker: false nexttasks: '#none#': - "3" note: false quietmode: 0 separatecontext: false skipunavailable: false task: brand: "" id: 582019ae-12f5-4b29-823b-a79ef3543d00 iscommand: false name: Cortex XDR monitors for behavioral events along a causality chain to identify discovery behaviors type: title version: -1 description: '' taskid: 582019ae-12f5-4b29-823b-a79ef3543d00 timertriggers: [] type: title view: |- { "position": { "x": 265, "y": 50 } } "6": id: "6" ignoreworker: false nexttasks: '#none#': - "7" note: false quietmode: 0 scriptarguments: append: simple: "true" key: simple: Handled.Techniques stringify: {} value: simple: T1083 separatecontext: false skipunavailable: false task: brand: "" description: Set a value in context under the key you entered. id: 27993e33-d2f9-48bc-83bb-fa66d7382af7 iscommand: false name: Set technique handled script: Set type: regular version: -1 taskid: 27993e33-d2f9-48bc-83bb-fa66d7382af7 timertriggers: [] type: regular view: |- { "position": { "x": 265, "y": 720 } } "7": continueonerror: true id: "7" ignoreworker: false nexttasks: '#none#': - "2" note: false quietmode: 0 scriptarguments: columns: simple: technique context_path: simple: Handled.Techniques grid_id: simple: handledtechniques keys: {} overwrite: {} sort_by: {} unpack_nested_elements: {} separatecontext: false skipunavailable: false task: brand: "" description: Creates a Grid table from items or key-value pairs. id: 1583d9e0-c780-4d30-8040-58036211ef81 iscommand: false name: Set grid field script: SetGridField type: regular version: -1 taskid: 1583d9e0-c780-4d30-8040-58036211ef81 timertriggers: [] type: regular view: |- { "position": { "x": 265, "y": 900 } } version: -1 view: |- { "linkLabelsPosition": { "3_1_yes": 0.41 }, "paper": { "dimensions": { "height": 1265, "width": 635, "x": 265, "y": -110 } } } tests: - No tests (auto formatted) fromversion: 6.5.0