TACTIC: DISCOVERY

File and Directory Discovery (T1083): real cases

MITRE Definition ↗
Adversaries search file systems and shared drives for sensitive files and trade secrets.

Key Facts

Technique ID
T1083
Discovery
Mapped Cases
1
Primary sources
Related Laws
0
Criminal statutes
  • ATT&CK Technique Identifier: T1083.
  • Tactical Phase: Discovery.
  • Substantiated in 1 primary court prosecution cases.
  • Every associated case includes verbatim evidentiary excerpts from indictments or sworn affidavits.

Verified Evidentiary Case Records

Primary Source Evidence Excerpt: Indictment ¶ 12, Page 6
"Thompson ran automated aws-s3 listing commands to enumerate bucket contents across victim customer directories."
U.S. District Court for the Western District of Washington View full case dossier →