What is file and directory discovery?¶
File and directory discovery is searching for files, folders, shares or repositories that look useful.
For an investigator, the value is often in the names and paths returned. They can tell you what the session was interested in and give you exact values to look for in later file-access or transfer records.
What might somebody search for?¶
A session might look for:
- finance folders;
- customer files;
- password or credential documents;
- spreadsheets;
- archives;
- shared drives; or
- particular filenames or extensions.
A saved result might look like:
\\FIN-SRV-04\Finance
Q4-payments.xlsx
Customers-2026.csv
backup-credentials.txt
Those values are immediately useful.
Search later records for the same share, filename or path.
Keep the stages separate¶
Finding a file is not the same as opening it.
Opening it is not the same as copying it.
Copying it is not the same as sending it somewhere else.
Keeping those stages separate makes the timeline much clearer.
Search terms can be useful evidence too¶
If somebody searches specifically for words such as “payments”, “customers” or “password”, that may help show what information they were trying to locate.
Search history, command output, recent items, indexes or temporary files may preserve part of that activity.
Again, that does not automatically prove the material was obtained. It gives you a line of enquiry.
Normal software also enumerates files¶
Backup systems, search indexers, antivirus tools and ordinary applications all inspect files and folders.
A focused search followed by copying or archive creation looks very different from a background indexing service touching thousands of files as part of its normal job.
The practical point is: file discovery tells you what was being looked for. Reuse the returned filenames and paths to find out whether anything was actually opened, collected or transferred.