Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1083 File and Directory Discovery |
MalwareCanisterWorm | CanisterWorm has discovered npm pathways and directories that frequently store .npmrc files to check for _authToken values. |
| T1083 File and Directory Discovery |
MalwareBADFLICK | BADFLICK has searched for files on the infected host. |
| T1087 Account Discovery |
MalwareHavoc | Havoc can identify privileged user accounts on infected systems. |
| T1087 Account Discovery |
MalwareTONESHELL | TONESHELL included functionality to retrieve a list of user accounts. |
| T1087 Account Discovery |
MalwareWoody RAT | Woody RAT can identify administrator accounts on an infected machine. |
| T1087 Account Discovery |
MalwareXCSSET | XCSSET attempts to discover accounts from various locations such as a user's Evernote, AppleID, Telegram, Skype, and WeChat data. |
| T1087 Account Discovery |
ToolShimRatReporter | ShimRatReporter listed all non-privileged and privileged accounts available on the machine. |
| T1087.001 Local Account |
MalwareTrickBot | TrickBot collects the users of the system. |
| T1087.001 Local Account |
MalwarePikabot | Pikabot will retrieve the name of the user associated with the thread under which the malware is executing. |
| T1087.001 Local Account |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about users on remote hosts. |
| T1087.001 Local Account |
MalwareStuxnet | Stuxnet enumerates user accounts of the local host. |
| T1087.001 Local Account |
MalwareGeminiDuke | GeminiDuke collects information on local user accounts from the victim. |
| T1087.001 Local Account |
MalwareInvisibleFerret | InvisibleFerret has queried the victim device using Python scripts to obtain the User and Hostname. |
| T1087.001 Local Account |
MalwareBankshot | Bankshot gathers domain and account names/information through process monitoring. |
| T1087.001 Local Account |
MalwarePony | Pony has used the |
| T1087.001 Local Account |
MalwareHyperStack | HyperStack can enumerate all account names on a remote share. |
| T1087.001 Local Account |
MalwareDUSTTRAP | DUSTTRAP can enumerate local user accounts. |
| T1087.001 Local Account |
MalwareSystemBC | SystemBC has collected the Windows account username on the victim machine. |
| T1087.001 Local Account |
MalwareInvisiMole | InvisiMole has a command to list account information on the victim’s machine. |
| T1087.001 Local Account |
MalwareP.A.S. Webshell | P.A.S. Webshell can display the /etc/passwd file on a compromised host. |
| T1087.001 Local Account |
MalwareKazuar | Kazuar gathers information on local groups and members on the victim’s machine. |
| T1087.001 Local Account |
MalwareSHOTPUT | SHOTPUT has a command to retrieve information about connected users. |
| T1087.001 Local Account |
MalwarePUNCHBUGGY | PUNCHBUGGY can gather user names. |
| T1087.001 Local Account |
MalwareS-Type | S-Type has run the command `net user` on a victim. |
| T1087.001 Local Account |
MalwareRemsec | Remsec can obtain a list of users. |
| T1087.001 Local Account |
MalwareEpic | Epic gathers a list of all user accounts, privilege classes, and time of last logon. |
| T1087.001 Local Account |
MalwareElise | Elise executes |
| T1087.001 Local Account |
MalwareUSBferry | USBferry can use |
| T1087.001 Local Account |
MalwareSMOKEDHAM | SMOKEDHAM has used |
| T1087.001 Local Account |
MalwareRedLine Stealer | RedLine Stealer has collected account information from the victim’s machine. |
| T1087.001 Local Account |
MalwareBazar | Bazar can identify administrator accounts on an infected host. |
| T1087.001 Local Account |
MalwareRATANKBA | RATANKBA uses the |
| T1087.001 Local Account |
MalwareMgBot | MgBot includes modules for identifying local administrator accounts on victim systems. |
| T1087.001 Local Account |
MalwareValak | Valak has the ability to enumerate local admin accounts. |
| T1087.001 Local Account |
MalwareMilan | Milan has run `C:\Windows\system32\cmd.exe /c cmd /c dir c:\users\ /s 2>&1` to discover local accounts. |
| T1087.001 Local Account |
MalwareRaccoon Stealer | Raccoon Stealer checks the privileges of running processes to determine if the running user is equivalent to `NT Authority\System`. |
| T1087.001 Local Account |
MalwareKwampirs | Kwampirs collects a list of accounts with the command |
| T1087.001 Local Account |
MalwareMis-Type | Mis-Type may create a file containing the results of the command |
| T1087.001 Local Account |
MalwareQilin | Qilin can list all local users found on a targeted system. |
| T1087.001 Local Account |
MalwareSoreFang | SoreFang can collect usernames from the local system via |
| T1087.001 Local Account |
MalwareAgent Tesla | Agent Tesla can collect account information from the victim’s machine. |
| T1087.001 Local Account |
MalwarePOWERSTATS | POWERSTATS can retrieve usernames from compromised hosts. |
| T1087.001 Local Account |
MalwareComnie | Comnie uses the |
| T1087.001 Local Account |
MalwareOSInfo | OSInfo enumerates local and domain users |
| T1087.001 Local Account |
MalwareBitPaymer | BitPaymer can enumerate the sessions for each user logged onto the infected host. |
| T1087.001 Local Account |
ToolNet | Commands under |
| T1087.001 Local Account |
ToolBloodHound | BloodHound can identify users with local administrator rights. |
| T1087.001 Local Account |
ToolPowerSploit | PowerSploit's |
| T1087.001 Local Account |
ToolEmpire | Empire can acquire local and domain user account information. |
| T1087.001 Local Account |
ToolPoshC2 | PoshC2 can enumerate local and domain user account information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.