ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

17136 examples

TechniqueUsed byProcedure example
T1087.001
Local Account
ToolEmpire

Empire can acquire local and domain user account information.

T1087.001
Local Account
ToolPoshC2

PoshC2 can enumerate local and domain user account information.

T1087.001
Local Account
ToolPupy

Pupy uses PowerView and Pywerview to perform discovery commands such as net user, net group, net local group, etc.

T1087.001
Local Account
MalwareDuqu

The discovery modules used with Duqu can collect information on accounts and permissions.

T1087.002
Domain Account
CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts.

T1087.002
Domain Account
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`.

T1087.002
Domain Account
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `dsquery` and `dsget` commands to get domain environment information and to query users in administrative groups.

T1087.002
Domain Account
CampaignOperation Wocao

During Operation Wocao, threat actors used the `net` command to retrieve information about domain accounts.

T1087.002
Domain Account
GroupBlackByte

BlackByte has used tools such as AdFind to identify and enumerate domain accounts.

T1087.002
Domain Account
GroupVolt Typhoon

Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery.

T1087.002
Domain Account
GroupAPT41

APT41 used built-in net commands to enumerate domain administrator users.

T1087.002
Domain Account
GroupDragonfly

Dragonfly has used batch scripts to enumerate users on a victim domain controller.

T1087.002
Domain Account
GroupmenuPass

menuPass has used the Microsoft administration tool csvde.exe to export Active Directory data.

T1087.002
Domain Account
GroupMuddyWater

MuddyWater has used cmd.exe net user /domain to enumerate domain users.

T1087.002
Domain Account
GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1087.002
Domain Account
GroupStorm-1811

Storm-1811 has performed domain account enumeration during intrusions.

T1087.002
Domain Account
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information.

T1087.002
Domain Account
GroupSandworm Team

Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about usernames listed in AD.

T1087.002
Domain Account
GroupMustang Panda

Mustang Panda has utilized AdFind to identify domain users.

T1087.002
Domain Account
GroupScattered Spider

Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment.

T1087.002
Domain Account
GroupOilRig

OilRig has run net user, net user /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to get account listings on a victim.

T1087.002
Domain Account
GroupKe3chang

Ke3chang performs account discovery using commands such as net localgroup administrators and net group "REDACTED" /domain on specific permissions groups.

T1087.002
Domain Account
GroupTurla

Turla has used net user /domain to enumerate domain accounts.

T1087.002
Domain Account
GroupStorm-0501

Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts.

T1087.002
Domain Account
GroupPoseidon Group

Poseidon Group searches for administrator accounts on both the local victim machine and the network.

T1087.002
Domain Account
GroupRedCurl

RedCurl has collected information about domain accounts using SysInternal’s AdExplorer functionality .

T1087.002
Domain Account
GroupLotus Blossom

Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries.

T1087.002
Domain Account
GroupChimera

Chimera has has used net user /dom and net user Administrator to enumerate domain accounts including administrator accounts.

T1087.002
Domain Account
GroupMirrorFace

MirrorFace has used native Windows tools to obtain domain user information.

T1087.002
Domain Account
GroupBRONZE BUTLER

BRONZE BUTLER has used net user /domain to identify account information.

T1087.002
Domain Account
GroupToddyCat

ToddyCat has run `net user %USER% /dom` for account discovery.

T1087.002
Domain Account
GroupFox Kitten

Fox Kitten has used the Softerra LDAP browser to browse documentation on service accounts.

T1087.002
Domain Account
GroupINC Ransom

INC Ransom has scanned for domain admin accounts in compromised environments.

T1087.002
Domain Account
GroupLAPSUS$

LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network.

T1087.002
Domain Account
GroupWizard Spider

Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data.

T1087.002
Domain Account
GroupVOID MANTICORE

VOID MANTICORE has utilized ADRecon to enumerate the active directory environment.

T1087.002
Domain Account
GroupFIN13

FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`.

T1087.002
Domain Account
MalwareStuxnet

Stuxnet enumerates user accounts of the domain.

T1087.002
Domain Account
MalwarePOWRUNER

POWRUNER may collect user account information by running net user /domain or a series of other commands on a victim.

T1087.002
Domain Account
MalwareBankshot

Bankshot gathers domain and account names/information through process monitoring.

T1087.002
Domain Account
MalwareDUSTTRAP

DUSTTRAP can enumerate domain accounts.

T1087.002
Domain Account
MalwareRustyWater

RustyWater has gathered the domain membership of the victim machine’s user.

T1087.002
Domain Account
MalwareBlackCat

BlackCat can utilize `net use` commands to identify domain users.

T1087.002
Domain Account
MalwareIcedID

IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect.

T1087.002
Domain Account
MalwareSykipot

Sykipot may use net group "domain admins" /domain to display accounts in the "domain admins" permissions group and net localgroup "administrators" to list local system administrator group membership.

T1087.002
Domain Account
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c net group "Domain Admins" /domain` to identify domain administrator accounts.

T1087.002
Domain Account
MalwareBazar

Bazar has the ability to identify domain administrator accounts.

T1087.002
Domain Account
MalwareMgBot

MgBot includes modules for collecting information on Active Directory domain accounts.

T1087.002
Domain Account
MalwareCobalt Strike

Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group.

T1087.002
Domain Account
MalwareValak

Valak has the ability to enumerate domain admin accounts.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.