Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1087.001 Local Account |
ToolEmpire | Empire can acquire local and domain user account information. |
| T1087.001 Local Account |
ToolPoshC2 | PoshC2 can enumerate local and domain user account information. |
| T1087.001 Local Account |
ToolPupy | Pupy uses PowerView and Pywerview to perform discovery commands such as net user, net group, net local group, etc. |
| T1087.001 Local Account |
MalwareDuqu | The discovery modules used with Duqu can collect information on accounts and permissions. |
| T1087.002 Domain Account |
CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts. |
| T1087.002 Domain Account |
CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`. |
| T1087.002 Domain Account |
CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `dsquery` and `dsget` commands to get domain environment information and to query users in administrative groups. |
| T1087.002 Domain Account |
CampaignOperation Wocao | During Operation Wocao, threat actors used the `net` command to retrieve information about domain accounts. |
| T1087.002 Domain Account |
GroupBlackByte | BlackByte has used tools such as AdFind to identify and enumerate domain accounts. |
| T1087.002 Domain Account |
GroupVolt Typhoon | Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery. |
| T1087.002 Domain Account |
GroupAPT41 | APT41 used built-in |
| T1087.002 Domain Account |
GroupDragonfly | Dragonfly has used batch scripts to enumerate users on a victim domain controller. |
| T1087.002 Domain Account |
GroupmenuPass | menuPass has used the Microsoft administration tool csvde.exe to export Active Directory data. |
| T1087.002 Domain Account |
GroupMuddyWater | MuddyWater has used |
| T1087.002 Domain Account |
GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1087.002 Domain Account |
GroupStorm-1811 | Storm-1811 has performed domain account enumeration during intrusions. |
| T1087.002 Domain Account |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information. |
| T1087.002 Domain Account |
GroupSandworm Team | Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about usernames listed in AD. |
| T1087.002 Domain Account |
GroupMustang Panda | Mustang Panda has utilized AdFind to identify domain users. |
| T1087.002 Domain Account |
GroupScattered Spider | Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment. |
| T1087.002 Domain Account |
GroupOilRig | OilRig has run |
| T1087.002 Domain Account |
GroupKe3chang | Ke3chang performs account discovery using commands such as |
| T1087.002 Domain Account |
GroupTurla | Turla has used |
| T1087.002 Domain Account |
GroupStorm-0501 | Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts. |
| T1087.002 Domain Account |
GroupPoseidon Group | Poseidon Group searches for administrator accounts on both the local victim machine and the network. |
| T1087.002 Domain Account |
GroupRedCurl | RedCurl has collected information about domain accounts using SysInternal’s AdExplorer functionality . |
| T1087.002 Domain Account |
GroupLotus Blossom | Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries. |
| T1087.002 Domain Account |
GroupChimera | Chimera has has used |
| T1087.002 Domain Account |
GroupMirrorFace | MirrorFace has used native Windows tools to obtain domain user information. |
| T1087.002 Domain Account |
GroupBRONZE BUTLER | BRONZE BUTLER has used |
| T1087.002 Domain Account |
GroupToddyCat | ToddyCat has run `net user %USER% /dom` for account discovery. |
| T1087.002 Domain Account |
GroupFox Kitten | Fox Kitten has used the Softerra LDAP browser to browse documentation on service accounts. |
| T1087.002 Domain Account |
GroupINC Ransom | INC Ransom has scanned for domain admin accounts in compromised environments. |
| T1087.002 Domain Account |
GroupLAPSUS$ | LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network. |
| T1087.002 Domain Account |
GroupWizard Spider | Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data. |
| T1087.002 Domain Account |
GroupVOID MANTICORE | VOID MANTICORE has utilized ADRecon to enumerate the active directory environment. |
| T1087.002 Domain Account |
GroupFIN13 | FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`. |
| T1087.002 Domain Account |
MalwareStuxnet | Stuxnet enumerates user accounts of the domain. |
| T1087.002 Domain Account |
MalwarePOWRUNER | POWRUNER may collect user account information by running |
| T1087.002 Domain Account |
MalwareBankshot | Bankshot gathers domain and account names/information through process monitoring. |
| T1087.002 Domain Account |
MalwareDUSTTRAP | DUSTTRAP can enumerate domain accounts. |
| T1087.002 Domain Account |
MalwareRustyWater | RustyWater has gathered the domain membership of the victim machine’s user. |
| T1087.002 Domain Account |
MalwareBlackCat | BlackCat can utilize `net use` commands to identify domain users. |
| T1087.002 Domain Account |
MalwareIcedID | IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect. |
| T1087.002 Domain Account |
MalwareSykipot | Sykipot may use |
| T1087.002 Domain Account |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c net group "Domain Admins" /domain` to identify domain administrator accounts. |
| T1087.002 Domain Account |
MalwareBazar | Bazar has the ability to identify domain administrator accounts. |
| T1087.002 Domain Account |
MalwareMgBot | MgBot includes modules for collecting information on Active Directory domain accounts. |
| T1087.002 Domain Account |
MalwareCobalt Strike | Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group. |
| T1087.002 Domain Account |
MalwareValak | Valak has the ability to enumerate domain admin accounts. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.