---
updatedAt: 2026-09-16T22:16:45.000Z
---

Fetch the complete documentation index at: https://docs.validin.com/llms.txt. Use this file to discover all available pages before exploring further. Append .md to any documentation page URL to get its markdown version.

# Open Directories

Learn how to use Validin's Open Directories Explorer to hunt over content collected from exposed Open Directories

## What is an open directory?

An open directory is a web-accessible folder that displays a listing of its files and subdirectories. Visitors can browse the listing and access files without signing in. These pages often have titles such as “Index of /” and show filenames, sizes, and modification dates.

Some directories intentionally distribute public files. Others expose content through a server configuration mistake. An open directory alone does not establish malicious activity, but its contents can provide useful evidence during an investigation.

## What you can do with Open Directories

Validin collects directory listings and file content so you can investigate saved observations. Use Open Directories to:

* Find files by name, path, extension, size, content type, or hash.
* Identify directories hosted on a domain, IP address, network range, or port.
* Explore related files and subdirectories in a captured directory.
* Review saved file content and metadata.
* Compare captures to understand how a directory or file changed over time.

> **Note:** Open Directories is in beta. Features and coverage may change.

## Start a search

Open **Open Directories** in Validin. You can start with a domain or IP address, select a standing search from the landing page, or enter an Open Directories VQL query.

### Look up a host

Enter a domain or IP address directly in the search box:

```text
files.example.com
```

```text
192.0.2.10
```

For a specific file attribute, use VQL. For example, find crawls containing a fetched ZIP archive:

```vql
open_dir.file.ext = "zip"
```

Narrow that search to a host:

```vql
open_dir:(host = "files.example.com" AND file.ext = "zip")
```

See [VQL for Open Directories](/docs/vql-open-directories) for supported fields, operators, and examples.

### Browse the latest crawl feeds

The landing page includes standing searches for interesting queries of open directory attributes. These feeds are regularly updated with new matches.

Select **Run this search** to explore the underlying query. The query is displayed on each feed so you can adapt it to your investigation.

## Review search results

Searches identify matching crawls: saved collection runs for an open directory. The same location can have multiple captures over time.

Expand a result to review the crawl details and, for searches on file attributes, the files that contributed to the match. Follow a directory or file link to open it in the Explorer.

Use **Group & view** to choose the information displayed and adjust how results are grouped. The displayed grouping can combine multiple underlying matches.

> **Note:** A **Partial results** message means more matches may exist. Narrow the query when a search reaches a result or time limit.

## Explore a directory

The Explorer displays the selected capture and its directory contents. Open a fetched subdirectory to move deeper into the listing, or use the breadcrumb links at the top to return to a parent directory.

Directory and file details can include names, paths, sizes, modification times, HTTP response information, and content types, depending on what was collected. Use the table controls to sort and filter the listing.

### Fetched files and listed files

A directory listing can advertise more files than Validin captured.

| State                  | What it means                                                                                                                   |
| ---------------------- | ------------------------------------------------------------------------------------------------------------------------------- |
| Fetched                | Validin captured the item and can show the available metadata and content.                                                      |
| Listed but not fetched | The item appeared in a listing, but Validin did not capture its contents in that crawl due to an error, timeout, or file limit. |

By default, searches using `file.name`, `file.path`, and `file.ext` match fetched files. Use the corresponding `file.listed.*` field to include files advertised in listings:

```vql
open_dir.file.listed.ext = "zip"
```

## Inspect a file

Open a fetched file to review its details and available preview. Metadata may include:

* The filename, path, size, and modification time.
* The content type reported by the server.
* Content types identified from the captured bytes by Magika or libmagic.
* SHA-256, SHA-1, and MD5 hashes.

The extension and server-reported content type may differ from the detected content type. Comparing them can help identify files whose names do not describe their contents.

### Preview and download content

Depending on the file and available capture, the Explorer shows text, an image, or a hexadecimal preview of binary data. Select **Load More** when available to display more captured content.

Select **Download** to save the captured file and follow the download prompt.

A preview may show only the beginning of a file. The capture itself may also be partial (large files are truncated at approximately 1 GB). Check the metadata: downloading an incomplete capture does not recover bytes that Validin did not collect.

## Review history

Select **Last Fetched** or **Last captured** at the top of the Explorer to open the history panel. Select **View** beside another capture to inspect it.

For files and subdirectories, history distinguishes a saved capture from an observation in a later parent crawl:

| History state                     | Meaning                                                          |
| --------------------------------- | ---------------------------------------------------------------- |
| Captured                          | A saved capture is available.                                    |
| No longer listed                  | The item was not present in the observed listing.                |
| Listed but not fetched            | The listing included the item, but its content was not captured. |
| Unknown - crawl failed/incomplete | The crawl could not establish the item's state.                  |

The latest saved capture may be older than the latest crawl. Review both to figure out whether a file remains available. History may be limited to recent crawls and the capture you are viewing; the panel identifies this when applicable.

## Compare captures

In the history panel, select **Diff** beside another capture to compare it with the one you are viewing.

Directory comparisons show added, removed, and changed entries. File comparisons show available content or metadata changes.&#x20;

## Save an investigation

Use the bookmark icon to save a search or the directory or file capture you are viewing. Add a note to preserve the context for your investigation.

<br />