Windows CMD dir /S File and Subfolder Enumeration
Flags cmd.exe executions using dir with the /S flag to enumerate files in a directory and all subdirectories.
- Product
- windows
- Category
- process_creation
- Author
- frack113 (SigmaHQ), DRL 1.1
- Published
- 2021-12-13
- Updated
- 2026-07-31
ATT&CK techniques
DiscoveryRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule identifies process executions of Windows Command Prompt (cmd.exe) where the command line includes the 'dir ' output pattern and the '/S' flag to enumerate files within a specified directory and its subdirectories. Attackers may use this discovery behavior to inventory accessible files prior to further actions. It relies on process creation telemetry capturing cmd.exe (by image or OriginalFileName) and the command line containing the relevant 'dir ' and '/S' indicators, while excluding command lines that include 'rmdir'.
Reporting behind it
Changelog
v2- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Windows CMD dir /S File and Subfolder Enumeration
id: 3dc2d80a-30d5-4fcd-a53c-c7897a549631
status: test
description: This rule identifies process executions of Windows Command Prompt (cmd.exe) where the command line includes the 'dir ' output pattern and the '/S' flag to enumerate files within a specified directory and its subdirectories. Attackers may use this discovery behavior to inventory accessible files prior to further actions. It relies on process creation telemetry capturing cmd.exe (by image or OriginalFileName) and the command line containing the relevant 'dir ' and '/S' indicators, while excluding command lines that include 'rmdir'.
references:
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1217/T1217.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_cmd_dir_execution.yml
author: frack113, Huntrule Team
date: 2021-12-13
modified: 2026-05-18
tags:
- attack.discovery
- attack.t1217
logsource:
category: process_creation
product: windows
detection:
selection_cmd:
- Image|endswith: \cmd.exe
- OriginalFileName: Cmd.Exe
selection_cli:
CommandLine|contains|windash: -s
CommandLine|contains: "dir "
filter_main_rmdir:
CommandLine|contains: rmdir
condition: all of selection_* and not 1 of filter_main_*
falsepositives:
- Likely
level: low
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_cmd_dir_execution/info.yml
simulation:
- type: atomic-red-team
name: List Internet Explorer Bookmarks using the command prompt
technique: T1217
atomic_guid: 727dbcdb-e495-4ab1-a6c4-80c7f77aef85
license: DRL-1.1
related:
- id: 7c9340a9-e2ee-4e43-94c5-c54ebbea1006
type: derived