Open Directories

Learn how to use Validin's Open Directories Explorer to hunt over content collected from exposed Open Directories

What is an open directory?

An open directory is a web-accessible folder that displays a listing of its files and subdirectories. Visitors can browse the listing and access files without signing in. These pages often have titles such as “Index of /” and show filenames, sizes, and modification dates.

Some directories intentionally distribute public files. Others expose content through a server configuration mistake. An open directory alone does not establish malicious activity, but its contents can provide useful evidence during an investigation.

What you can do with Open Directories

Validin collects directory listings and file content so you can investigate saved observations. Use Open Directories to:

  • Find files by name, path, extension, size, content type, or hash.
  • Identify directories hosted on a domain, IP address, network range, or port.
  • Explore related files and subdirectories in a captured directory.
  • Review saved file content and metadata.
  • Compare captures to understand how a directory or file changed over time.

Note: Open Directories is in beta. Features and coverage may change.

Start a search

Open Open Directories in Validin. You can start with a domain or IP address, select a standing search from the landing page, or enter an Open Directories VQL query.

Look up a host

Enter a domain or IP address directly in the search box:

files.example.com
192.0.2.10

For a specific file attribute, use VQL. For example, find crawls containing a fetched ZIP archive:

open_dir.file.ext = "zip"

Narrow that search to a host:

open_dir:(host = "files.example.com" AND file.ext = "zip")

See VQL for Open Directories for supported fields, operators, and examples.

Browse the latest crawl feeds

The landing page includes standing searches for interesting queries of open directory attributes. These feeds are regularly updated with new matches.

Select Run this search to explore the underlying query. The query is displayed on each feed so you can adapt it to your investigation.

Review search results

Searches identify matching crawls: saved collection runs for an open directory. The same location can have multiple captures over time.

Expand a result to review the crawl details and, for searches on file attributes, the files that contributed to the match. Follow a directory or file link to open it in the Explorer.

Use Group & view to choose the information displayed and adjust how results are grouped. The displayed grouping can combine multiple underlying matches.

Note: A Partial results message means more matches may exist. Narrow the query when a search reaches a result or time limit.

Explore a directory

The Explorer displays the selected capture and its directory contents. Open a fetched subdirectory to move deeper into the listing, or use the breadcrumb links at the top to return to a parent directory.

Directory and file details can include names, paths, sizes, modification times, HTTP response information, and content types, depending on what was collected. Use the table controls to sort and filter the listing.

Fetched files and listed files

A directory listing can advertise more files than Validin captured.

StateWhat it means
FetchedValidin captured the item and can show the available metadata and content.
Listed but not fetchedThe item appeared in a listing, but Validin did not capture its contents in that crawl due to an error, timeout, or file limit.

By default, searches using file.name, file.path, and file.ext match fetched files. Use the corresponding file.listed.* field to include files advertised in listings:

open_dir.file.listed.ext = "zip"

Inspect a file

Open a fetched file to review its details and available preview. Metadata may include:

  • The filename, path, size, and modification time.
  • The content type reported by the server.
  • Content types identified from the captured bytes by Magika or libmagic.
  • SHA-256, SHA-1, and MD5 hashes.

The extension and server-reported content type may differ from the detected content type. Comparing them can help identify files whose names do not describe their contents.

Preview and download content

Depending on the file and available capture, the Explorer shows text, an image, or a hexadecimal preview of binary data. Select Load More when available to display more captured content.

Select Download to save the captured file and follow the download prompt.

A preview may show only the beginning of a file. The capture itself may also be partial (large files are truncated at approximately 1 GB). Check the metadata: downloading an incomplete capture does not recover bytes that Validin did not collect.

Review history

Select Last Fetched or Last captured at the top of the Explorer to open the history panel. Select View beside another capture to inspect it.

For files and subdirectories, history distinguishes a saved capture from an observation in a later parent crawl:

History stateMeaning
CapturedA saved capture is available.
No longer listedThe item was not present in the observed listing.
Listed but not fetchedThe listing included the item, but its content was not captured.
Unknown - crawl failed/incompleteThe crawl could not establish the item's state.

The latest saved capture may be older than the latest crawl. Review both to figure out whether a file remains available. History may be limited to recent crawls and the capture you are viewing; the panel identifies this when applicable.

Compare captures

In the history panel, select Diff beside another capture to compare it with the one you are viewing.

Directory comparisons show added, removed, and changed entries. File comparisons show available content or metadata changes.

Save an investigation

Use the bookmark icon to save a search or the directory or file capture you are viewing. Add a note to preserve the context for your investigation.



Did this page help you?