Real-world descriptions of how a group, tool or campaign used a technique.
196 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareBonadan | Bonadan has discovered the username of the user running the backdoor. |
| T1033 System Owner/User Discovery |
MalwareNeoichor | Neoichor can collect the user name from a victim's machine. |
| T1033 System Owner/User Discovery |
MalwareRaspberry Robin | Raspberry Robin determines whether it is successfully running on a victim system by querying the running account information to determine if it is running in Session 0, indicating running with elevated privileges. |
| T1033 System Owner/User Discovery |
MalwareDiavol | Diavol can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareRustyWater | RustyWater has gathered the victim machine’s username. |
| T1033 System Owner/User Discovery |
MalwareBlackCat | BlackCat can utilize `net use` commands to discover the user name on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareVERMIN | VERMIN gathers the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareNightdoor | Nightdoor gathers information on victim system users and usernames. |
| T1033 System Owner/User Discovery |
MalwareMarkiRAT | MarkiRAT can retrieve the victim’s username. |
| T1033 System Owner/User Discovery |
MalwarePowerShower | PowerShower has the ability to identify the current user on the infected host. |
| T1033 System Owner/User Discovery |
MalwareKazuar | Kazuar gathers information on users. |
| T1033 System Owner/User Discovery |
MalwareDarkComet | DarkComet gathers the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has included the victim's computer name and username in C2 messages sent to actor-owned infrastructure. |
| T1033 System Owner/User Discovery |
MalwareLucifer | Lucifer has the ability to identify the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwarezwShell | zwShell can obtain the name of the logged-in user on the victim. |
| T1033 System Owner/User Discovery |
MalwareDRATzarus | DRATzarus can obtain a list of users from an infected machine. |
| T1033 System Owner/User Discovery |
MalwareRising Sun | Rising Sun can detect the username of the infected host. |
| T1033 System Owner/User Discovery |
MalwareChrommme | Chrommme can retrieve the username from a targeted system. |
| T1033 System Owner/User Discovery |
MalwareObliqueRAT | ObliqueRAT can check for blocklisted usernames on infected endpoints. |
| T1033 System Owner/User Discovery |
MalwareSocGholish | SocGholish can use `whoami` to obtain the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareFlagpro | Flagpro has been used to run the |
| T1033 System Owner/User Discovery |
MalwareXAgentOSX | XAgentOSX contains the getInfoOSX function to return the OS X version as well as the current user. |
| T1033 System Owner/User Discovery |
MalwareROKRAT | ROKRAT can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareDarkWatchman | DarkWatchman has collected the username from a victim machine. |
| T1033 System Owner/User Discovery |
MalwareDyre | Dyre has the ability to identify the users on a compromised host. |
| T1033 System Owner/User Discovery |
MalwarePlugX | PlugX has the ability to gather the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareReaver | Reaver collects the victim's username. |
| T1033 System Owner/User Discovery |
MalwareS-Type | S-Type has run tests to determine the privilege level of the compromised user. |
| T1033 System Owner/User Discovery |
MalwareRemsec | Remsec can obtain information about the current user. |
| T1033 System Owner/User Discovery |
MalwareExplosive | Explosive has collected the username from the infected host. |
| T1033 System Owner/User Discovery |
MalwareEpic | Epic collects the user name from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareClambling | Clambling can identify the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwarePureCrypter | PureCrypter can retrieve the username from targeted machines. |
| T1033 System Owner/User Discovery |
MalwareNanHaiShu | NanHaiShu collects the username from the victim. |
| T1033 System Owner/User Discovery |
MalwareSVCReady | SVCReady can collect the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwareNGLite | NGLite will run the |
| T1033 System Owner/User Discovery |
MalwareSHARPSTATS | SHARPSTATS has the ability to identify the username on the compromised host. |
| T1033 System Owner/User Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can obtain a list of user accounts from a victim's machine. |
| T1033 System Owner/User Discovery |
MalwareGazer | Gazer obtains the current user's security identifier. |
| T1033 System Owner/User Discovery |
MalwareLatrodectus | Latrodectus can discover the username of an infected host. |
| T1033 System Owner/User Discovery |
MalwareSaint Bot | Saint Bot can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareChaes | Chaes has collected the username and UID from the infected machine. |
| T1033 System Owner/User Discovery |
MalwareLODEINFO | LODEINFO can identify the associated username on targeted machines. |
| T1033 System Owner/User Discovery |
MalwareEVILNUM | EVILNUM can obtain the username from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareSMOKEDHAM | SMOKEDHAM has used |
| T1033 System Owner/User Discovery |
MalwareQUADAGENT | QUADAGENT gathers the victim username. |
| T1033 System Owner/User Discovery |
MalwareSys10 | Sys10 collects the account name of the logged-in user and sends it to the C2. |
| T1033 System Owner/User Discovery |
MalwareMetamorfo | Metamorfo has collected the username from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can gather information about the user on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareKONNI | KONNI can collect the username from the victim’s machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.