Windows CMD "dir" Enumeration Using /S Subdirectory Flag
Flags cmd.exe executions using dir with the /S flag to enumerate files in a directory and all subdirectories.
FreeUnreviewedSigmalowv1
windows-cmd-dir-enumeration-using-s-subdirectory-flag-7c9340a9
title: Windows CMD "dir" Enumeration Using /S Subdirectory Flag
id: 3dc2d80a-30d5-4fcd-a53c-c7897a549631
status: test
description: This rule identifies process executions of the Windows command prompt where the command line includes a "dir " invocation combined with the /S flag to enumerate files across a target directory and its subfolders. Attackers may use this discovery behavior to quickly inventory file structures and assess available data before further actions. It relies on process creation telemetry, matching cmd.exe execution and specific command-line substrings.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1217/T1217.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_cmd_dir_execution.yml
author: frack113, Huntrule Team
date: 2021-12-13
modified: 2026-05-18
tags:
- attack.discovery
- attack.t1217
logsource:
category: process_creation
product: windows
detection:
selection_cmd:
- Image|endswith: \cmd.exe
- OriginalFileName: Cmd.Exe
selection_cli:
CommandLine|contains|windash: -s
CommandLine|contains: "dir "
filter_main_rmdir:
CommandLine|contains: rmdir
condition: all of selection_* and not 1 of filter_main_*
falsepositives:
- Likely
level: low
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_cmd_dir_execution/info.yml
simulation:
- type: atomic-red-team
name: List Internet Explorer Bookmarks using the command prompt
technique: T1217
atomic_guid: 727dbcdb-e495-4ab1-a6c4-80c7f77aef85
license: DRL-1.1
related:
- id: 7c9340a9-e2ee-4e43-94c5-c54ebbea1006
type: derived
What it detects
This rule identifies process executions of the Windows command prompt where the command line includes a "dir " invocation combined with the /S flag to enumerate files across a target directory and its subfolders. Attackers may use this discovery behavior to quickly inventory file structures and assess available data before further actions. It relies on process creation telemetry, matching cmd.exe execution and specific command-line substrings.
Known false positives
- Likely
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.