Windows CMD "dir" Enumeration Using /S Subdirectory Flag

Flags cmd.exe executions using dir with the /S flag to enumerate files in a directory and all subdirectories.

FreeUnreviewedSigmalowv1
title: Windows CMD "dir" Enumeration Using /S Subdirectory Flag
id: 3dc2d80a-30d5-4fcd-a53c-c7897a549631
status: test
description: This rule identifies process executions of the Windows command prompt where the command line includes a "dir " invocation combined with the /S flag to enumerate files across a target directory and its subfolders. Attackers may use this discovery behavior to quickly inventory file structures and assess available data before further actions. It relies on process creation telemetry, matching cmd.exe execution and specific command-line substrings.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1217/T1217.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_cmd_dir_execution.yml
author: frack113, Huntrule Team
date: 2021-12-13
modified: 2026-05-18
tags:
  - attack.discovery
  - attack.t1217
logsource:
  category: process_creation
  product: windows
detection:
  selection_cmd:
    - Image|endswith: \cmd.exe
    - OriginalFileName: Cmd.Exe
  selection_cli:
    CommandLine|contains|windash: -s
    CommandLine|contains: "dir "
  filter_main_rmdir:
    CommandLine|contains: rmdir
  condition: all of selection_* and not 1 of filter_main_*
falsepositives:
  - Likely
level: low
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_cmd_dir_execution/info.yml
simulation:
  - type: atomic-red-team
    name: List Internet Explorer Bookmarks using the command prompt
    technique: T1217
    atomic_guid: 727dbcdb-e495-4ab1-a6c4-80c7f77aef85
license: DRL-1.1
related:
  - id: 7c9340a9-e2ee-4e43-94c5-c54ebbea1006
    type: derived

What it detects

This rule identifies process executions of the Windows command prompt where the command line includes a "dir " invocation combined with the /S flag to enumerate files across a target directory and its subfolders. Attackers may use this discovery behavior to quickly inventory file structures and assess available data before further actions. It relies on process creation telemetry, matching cmd.exe execution and specific command-line substrings.

Known false positives

  • Likely

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.