Real-world descriptions of how a group, tool or campaign used a technique.
196 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareTrickBot | TrickBot can identify the user and groups the user belongs to on a compromised host. |
| T1033 System Owner/User Discovery |
MalwarePowerDuke | PowerDuke has commands to get the current user's name and SID. |
| T1033 System Owner/User Discovery |
MalwareRCSession | RCSession can gather system owner information, including user and administrator privileges. |
| T1033 System Owner/User Discovery |
MalwareSpark | Spark has run the whoami command and has a built-in command to identify the user logged in. |
| T1033 System Owner/User Discovery |
MalwareSynAck | SynAck gathers user names from infected hosts. |
| T1033 System Owner/User Discovery |
MalwareBumblebee | Bumblebee has the ability to identify the user name. |
| T1033 System Owner/User Discovery |
MalwareAmadey | Amadey has collected the user name from a compromised host using `GetUserNameA`. |
| T1033 System Owner/User Discovery |
MalwareNOKKI | NOKKI can collect the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
Malwareyty | yty collects the victim’s username. |
| T1033 System Owner/User Discovery |
MalwareBackdoor.Oldrea | Backdoor.Oldrea collects the current username from the victim. |
| T1033 System Owner/User Discovery |
MalwareIronWind | IronWind can enumerate the username on victim's systems. |
| T1033 System Owner/User Discovery |
MalwareGet2 | Get2 has the ability to identify the current username of an infected host. |
| T1033 System Owner/User Discovery |
MalwarePOWRUNER | POWRUNER may collect information about the currently logged in user by running |
| T1033 System Owner/User Discovery |
MalwareKOPILUWAK | KOPILUWAK can conduct basic network reconnaissance on the victim machine with `whoami`, to get user details. |
| T1033 System Owner/User Discovery |
MalwareLinux Rabbit | Linux Rabbit opens a socket on port 22 and if it receives a response it attempts to obtain the machine's hostname and Top-Level Domain. |
| T1033 System Owner/User Discovery |
MalwareExaramel for Linux | Exaramel for Linux can run |
| T1033 System Owner/User Discovery |
MalwareHAWKBALL | HAWKBALL can collect the user name of the system. |
| T1033 System Owner/User Discovery |
MalwareRedLeaves | RedLeaves can obtain information about the logged on user both locally and for Remote Desktop sessions. |
| T1033 System Owner/User Discovery |
MalwareFelismus | Felismus collects the current username and sends it to the C2 server. |
| T1033 System Owner/User Discovery |
MalwareHavoc | Havoc can trigger exection of `whoami` on the target host to display the current user. |
| T1033 System Owner/User Discovery |
MalwareGravityRAT | GravityRAT collects the victim username along with other account information (account type, description, full name, SID and status). |
| T1033 System Owner/User Discovery |
MalwareInvisibleFerret | InvisibleFerret has identified the user’s UUID and username through the "pay" module. |
| T1033 System Owner/User Discovery |
MalwareHAPPYWORK | can collect the victim user name. |
| T1033 System Owner/User Discovery |
MalwareWinMM | WinMM uses NetUser-GetInfo to identify that it is running under an “Admin” account on the local system. |
| T1033 System Owner/User Discovery |
MalwareTONESHELL | TONESHELL has obtained the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwarePyDCrypt | PyDCrypt has probed victim machines with |
| T1033 System Owner/User Discovery |
MalwareBOOKWORM | BOOKWORM has obtained the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwareSslMM | SslMM sends the logged-on username to its hard-coded C2. |
| T1033 System Owner/User Discovery |
MalwareAria-body | Aria-body has the ability to identify the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareEmotet | Emotet has enumerated all users connected to network shares. |
| T1033 System Owner/User Discovery |
MalwareCrimson | Crimson can identify the user on a targeted system. |
| T1033 System Owner/User Discovery |
MalwareTurian | Turian can retrieve usernames. |
| T1033 System Owner/User Discovery |
MalwareBADHATCH | BADHATCH can obtain logged user information from a compromised machine and can execute the command `whoami.exe`. |
| T1033 System Owner/User Discovery |
MalwareAction RAT | Action RAT has the ability to collect the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwarePrikormka | A module in Prikormka collects information from the victim about the current user name. |
| T1033 System Owner/User Discovery |
MalwarePUBLOAD | PUBLOAD has obtained the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwareWellMess | WellMess can collect the username on the victim machine to send to C2. |
| T1033 System Owner/User Discovery |
MalwareWoody RAT | Woody RAT can retrieve a list of user accounts and usernames from an infected machine. |
| T1033 System Owner/User Discovery |
MalwareMafalda | Mafalda can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareSquirrelwaffle | Squirrelwaffle can collect the user name from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareHexEval Loader | HexEval Loader has collected the username from the victim host. |
| T1033 System Owner/User Discovery |
MalwareAuTo Stealer | AuTo Stealer has the ability to collect the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwareAgent.btz | Agent.btz obtains the victim username and saves it to a file. |
| T1033 System Owner/User Discovery |
MalwareSombRAT | SombRAT can execute |
| T1033 System Owner/User Discovery |
MalwareFlawedAmmyy | FlawedAmmyy enumerates the current user during the initial infection. |
| T1033 System Owner/User Discovery |
MalwareRifdoor | Rifdoor has the ability to identify the username on the compromised host. |
| T1033 System Owner/User Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can discover and send the username from a compromised host to C2. |
| T1033 System Owner/User Discovery |
MalwareInvisiMole | InvisiMole lists local users and session information. |
| T1033 System Owner/User Discovery |
MalwareWINERACK | WINERACK can gather information on the victim username. |
| T1033 System Owner/User Discovery |
MalwareOkrum | Okrum can collect the victim username. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.