# T1083 File and Directory Discovery

> As of 2026-10-05, T1083 (File and Directory Discovery) appears in 519 tracked threats, first reported 2022-04-07 and most recently 2026-10-02, with linked actors including TeamPCP, APT38, Contagious Interview; it most often appears alongside T1005 (Data from Local System).

- **Tracked threats:** 519 (197 critical, 285 high, 34 medium, 1 low)
- **First seen:** 2022-04-07
- **Last seen:** 2026-10-02
- **Threat actors:** 122
- **Detection rules:** 338 (counts only; Blue tier and above)

## Key facts

- **ID:** T1083
- **Framework:** MITRE ATT&CK
- **Tactics:** Discovery
- **Matrix:** Enterprise
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1083/

## Activity timeline

T1083 first appeared in tracked threats on 2022-04-07 and was most recently reported on 2026-10-02. The busiest month was 2026-07 with 214 reports, and 518 of the 519 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1083 File and Directory Discovery is catalogued by MITRE ATT&CK under the Discovery tactic in the Enterprise matrix. Threadlinqs maps 519 of 2623 tracked threats (19.8%) to it; by severity that is 197 critical, 285 high, 34 medium, 1 low.

Threats that use T1083 most often also use [T1005 Data from Local System](https://intel.threadlinqs.com/technique/T1005) (407 threats), [T1082 System Information Discovery](https://intel.threadlinqs.com/technique/T1082) (377 threats), [T1041 Exfiltration Over C2 Channel](https://intel.threadlinqs.com/technique/T1041) (337 threats), [T1027 Obfuscated Files or Information](https://intel.threadlinqs.com/technique/T1027) (325 threats), [T1059 Command and Scripting Interpreter](https://intel.threadlinqs.com/technique/T1059) (308 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

122 tracked threat actors appear in the threats that use T1083; the most frequent are [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) (23), [APT38](https://intel.threadlinqs.com/actor/APT38) (18), [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) (15), [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) (15), [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) (13).

## Data sources

Telemetry that can reveal T1083, per MITRE ATT&CK.

- Command — Command Execution
- Process — OS API Execution, Process Creation

## Threat actors using it

- [TeamPCP](https://intel.threadlinqs.com/actor/TeamPCP) — 23
- [APT38](https://intel.threadlinqs.com/actor/APT38) — 18
- [Contagious Interview](https://intel.threadlinqs.com/actor/Contagious%20Interview) — 15
- [Sapphire Sleet](https://intel.threadlinqs.com/actor/Sapphire%20Sleet) — 15
- [Lazarus Group](https://intel.threadlinqs.com/actor/Lazarus%20Group) — 13
- [Stardust Chollima](https://intel.threadlinqs.com/actor/Stardust%20Chollima) — 12
- [Andariel](https://intel.threadlinqs.com/actor/Andariel) — 11
- [WageMole](https://intel.threadlinqs.com/actor/WageMole) — 10
- [APT28](https://intel.threadlinqs.com/actor/APT28) — 8
- [UNC1069](https://intel.threadlinqs.com/actor/UNC1069) — 8
- [Contagious Interview - G1052](https://intel.threadlinqs.com/actor/Contagious%20Interview%20-%20G1052) — 7
- [APT43](https://intel.threadlinqs.com/actor/APT43) — 6

## Tracked threats

The 30 most recent of 519 tracked threats that use T1083.

- [Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign (UAT-11587)](https://intel.threadlinqs.com/threat/TL-2026-2848) — high — 2026-10-02
- [Malicious ChatGPT Custom GPT "Plus 5.6" Used in ClickFix Campaign Delivering RAT via DLL Sideloading of…](https://intel.threadlinqs.com/threat/TL-2026-2766) — high — 2026-09-29
- [NeedyMantis: Storm-3069 Post-Compromise Modular Malware in Targeted Operations](https://intel.threadlinqs.com/threat/TL-2026-2733) — high — 2026-09-28
- [CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)](https://intel.threadlinqs.com/threat/TL-2026-2623) — critical — 2026-09-22
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [StyleSmuggler — Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores](https://intel.threadlinqs.com/threat/TL-2026-2358) — critical — 2026-09-06
- [BraZetsu: AI-Enhanced Malware Toolkit Powers Exilware's Infected Marketplace IAB Operation](https://intel.threadlinqs.com/threat/TL-2026-2250) — high — 2026-08-31
- [PaperCut NG/MF Chained Zero-Day RCE (CVE-2026-82078 & CVE-2026-81578) Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2184) — critical — 2026-08-28
- [BlueDelta (GRU/APT28) Targets Defense and Diplomacy with HOOKEDGE Backdoor](https://intel.threadlinqs.com/threat/TL-2026-2173) — high — 2026-08-27
- [Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…](https://intel.threadlinqs.com/threat/TL-2026-2172) — critical — 2026-08-27
- [Popular Rust Crates arrayref, internment, append-only-vec Compromised in Build-Time Supply Chain Attack via…](https://intel.threadlinqs.com/threat/TL-2026-2085) — critical — 2026-08-20
- [Hackers Target Zimbra Servers in Active Exploitation Campaign via CVE-2026-73570 SNMP Command Injection](https://intel.threadlinqs.com/threat/TL-2026-2082) — critical — 2026-08-20
- [Critical Elementor Pro unauthenticated file upload vulnerability leads to RCE on WordPress sites…](https://intel.threadlinqs.com/threat/TL-2026-2079) — critical — 2026-08-20
- [Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820…](https://intel.threadlinqs.com/threat/TL-2026-1987) — critical — 2026-08-11
- [CVE-2026-65400: macOS Screen Sharing Authentication Bypass Grants Unauthenticated Root Access](https://intel.threadlinqs.com/threat/TL-2026-1925) — critical — 2026-08-07
- [Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures — Atomic Stealer (AMOS) and…](https://intel.threadlinqs.com/threat/TL-2026-1899) — high — 2026-08-05
- [OVSWrap (CVE-2026-64531): Linux kernel Open vSwitch datapath 16-bit nla_len wraparound local privilege…](https://intel.threadlinqs.com/threat/TL-2026-1887) — high — 2026-08-05
- [ChainDrop npm Supply-Chain Compromise: Self-Propagating Mini Shai-Hulud Credential-Stealing Worm Affecting…](https://intel.threadlinqs.com/threat/TL-2026-1875) — critical — 2026-08-04
- [ClickFix Campaign Uses EtherHiding to Deliver Node.js RAT, Infostealer, and Malicious Chrome Extension…](https://intel.threadlinqs.com/threat/TL-2026-1800) — high — 2026-07-31
- [North Korea's Lazarus Group Linked to Tool-Sharing with Gunra Ransomware Operators Against South Korean…](https://intel.threadlinqs.com/threat/TL-2026-1797) — high — 2026-07-31
- [1337_GWTK: Malware-as-a-Service C2 Platform Masquerading as Server Administration Tool (Markas Escobar)](https://intel.threadlinqs.com/threat/TL-2026-1791) — medium — 2026-07-31
- [Adobe Campaign Classic Critical Incorrect Authorization Flaw Enables Unauthenticated Remote Code Execution…](https://intel.threadlinqs.com/threat/TL-2026-1790) — critical — 2026-07-31
- [STAC4749 Campaign: Microsoft Teams Vishing Leads to Chaos Ransomware Deployment](https://intel.threadlinqs.com/threat/TL-2026-1776) — high — 2026-07-30
- [GenieLocker Ransomware: Toy Ghouls (Bearlyfy) Cross-Platform Attacks on Windows, Linux, and ESXi](https://intel.threadlinqs.com/threat/TL-2026-1773) — high — 2026-07-30
- [Operation Double Barrel: State-Sponsored Threat Group Ties to Gunra Ransomware Exploit Korean Financial…](https://intel.threadlinqs.com/threat/TL-2026-1766) — critical — 2026-07-30
- [Three Critical VMware Flaws (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876) Allow Auth Bypass, RCE, and VM…](https://intel.threadlinqs.com/threat/TL-2026-1764) — critical — 2026-07-29
- [Amazon: North Korea's Sapphire Sleet (Stardust Chollima/UNC1069) Compromises Axios, Debug, Chalk, and…](https://intel.threadlinqs.com/threat/TL-2026-1760) — critical — 2026-07-29
- [CVE-2026-20316: Cisco Secure Firewall Management Center Hard-coded Password Vulnerability Added to CISA KEV](https://intel.threadlinqs.com/threat/TL-2026-1759) — critical — 2026-07-29
- [CVE-2026-6516: Unauthenticated Remote Code Execution in ManageEngine ADAudit Plus (CVSS 10.0)](https://intel.threadlinqs.com/threat/TL-2026-1756) — critical — 2026-07-29
- [CVE-2026-66066 "KindaRails2Shell": Critical Ruby on Rails Active Storage Flaw Allows Unauthenticated…](https://intel.threadlinqs.com/threat/TL-2026-1755) — critical — 2026-07-29

## Related CVEs

CVEs referenced by the tracked threats that use T1083, most frequent first.

- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2026-56164](https://intel.threadlinqs.com/cve/CVE-2026-56164)
- [CVE-2026-55040](https://intel.threadlinqs.com/cve/CVE-2026-55040)
- [CVE-2025-8088](https://intel.threadlinqs.com/cve/CVE-2025-8088)
- [CVE-2026-45659](https://intel.threadlinqs.com/cve/CVE-2026-45659)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2026-48282](https://intel.threadlinqs.com/cve/CVE-2026-48282)
- [CVE-2026-58644](https://intel.threadlinqs.com/cve/CVE-2026-58644)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-32201](https://intel.threadlinqs.com/cve/CVE-2026-32201)
- [CVE-2026-45321](https://intel.threadlinqs.com/cve/CVE-2026-45321)
- [CVE-2026-48276](https://intel.threadlinqs.com/cve/CVE-2026-48276)
- [CVE-2026-48277](https://intel.threadlinqs.com/cve/CVE-2026-48277)
- [CVE-2026-48281](https://intel.threadlinqs.com/cve/CVE-2026-48281)
- [CVE-2026-50522](https://intel.threadlinqs.com/cve/CVE-2026-50522)
- [CVE-2026-56155](https://intel.threadlinqs.com/cve/CVE-2026-56155)
- [CVE-2023-4966](https://intel.threadlinqs.com/cve/CVE-2023-4966)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-64446](https://intel.threadlinqs.com/cve/CVE-2025-64446)
- [CVE-2025-9491](https://intel.threadlinqs.com/cve/CVE-2025-9491)
- [CVE-2026-0257](https://intel.threadlinqs.com/cve/CVE-2026-0257)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-21509](https://intel.threadlinqs.com/cve/CVE-2026-21509)
- [CVE-2026-25253](https://intel.threadlinqs.com/cve/CVE-2026-25253)
- [CVE-2026-33634](https://intel.threadlinqs.com/cve/CVE-2026-33634)
- [CVE-2026-48027](https://intel.threadlinqs.com/cve/CVE-2026-48027)

## Detection coverage

Threadlinqs maintains 338 detection rules mapped to T1083 (SPL 106, KQL 129, Sigma 100, other 3). Rule content is available to Blue tier accounts and above; this page shows counts only.

338 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1083
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
