Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareBADHATCH | BADHATCH can obtain logged user information from a compromised machine and can execute the command `whoami.exe`. |
| T1033 System Owner/User Discovery |
MalwareAction RAT | Action RAT has the ability to collect the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwarePrikormka | A module in Prikormka collects information from the victim about the current user name. |
| T1033 System Owner/User Discovery |
MalwarePUBLOAD | PUBLOAD has obtained the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwareWellMess | WellMess can collect the username on the victim machine to send to C2. |
| T1033 System Owner/User Discovery |
MalwareWoody RAT | Woody RAT can retrieve a list of user accounts and usernames from an infected machine. |
| T1033 System Owner/User Discovery |
MalwareMafalda | Mafalda can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareSquirrelwaffle | Squirrelwaffle can collect the user name from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareHexEval Loader | HexEval Loader has collected the username from the victim host. |
| T1033 System Owner/User Discovery |
MalwareAuTo Stealer | AuTo Stealer has the ability to collect the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwareAgent.btz | Agent.btz obtains the victim username and saves it to a file. |
| T1033 System Owner/User Discovery |
MalwareSombRAT | SombRAT can execute |
| T1033 System Owner/User Discovery |
MalwareFlawedAmmyy | FlawedAmmyy enumerates the current user during the initial infection. |
| T1033 System Owner/User Discovery |
MalwareRifdoor | Rifdoor has the ability to identify the username on the compromised host. |
| T1033 System Owner/User Discovery |
MalwareCuckoo Stealer | Cuckoo Stealer can discover and send the username from a compromised host to C2. |
| T1033 System Owner/User Discovery |
MalwareInvisiMole | InvisiMole lists local users and session information. |
| T1033 System Owner/User Discovery |
MalwareWINERACK | WINERACK can gather information on the victim username. |
| T1033 System Owner/User Discovery |
MalwareOkrum | Okrum can collect the victim username. |
| T1033 System Owner/User Discovery |
MalwareBonadan | Bonadan has discovered the username of the user running the backdoor. |
| T1033 System Owner/User Discovery |
MalwareNeoichor | Neoichor can collect the user name from a victim's machine. |
| T1033 System Owner/User Discovery |
MalwareRaspberry Robin | Raspberry Robin determines whether it is successfully running on a victim system by querying the running account information to determine if it is running in Session 0, indicating running with elevated privileges. |
| T1033 System Owner/User Discovery |
MalwareDiavol | Diavol can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareRustyWater | RustyWater has gathered the victim machine’s username. |
| T1033 System Owner/User Discovery |
MalwareBlackCat | BlackCat can utilize `net use` commands to discover the user name on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareVERMIN | VERMIN gathers the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareNightdoor | Nightdoor gathers information on victim system users and usernames. |
| T1033 System Owner/User Discovery |
MalwareMarkiRAT | MarkiRAT can retrieve the victim’s username. |
| T1033 System Owner/User Discovery |
MalwarePowerShower | PowerShower has the ability to identify the current user on the infected host. |
| T1033 System Owner/User Discovery |
MalwareKazuar | Kazuar gathers information on users. |
| T1033 System Owner/User Discovery |
MalwareDarkComet | DarkComet gathers the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareCHIMNEYSWEEP | CHIMNEYSWEEP has included the victim's computer name and username in C2 messages sent to actor-owned infrastructure. |
| T1033 System Owner/User Discovery |
MalwareLucifer | Lucifer has the ability to identify the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwarezwShell | zwShell can obtain the name of the logged-in user on the victim. |
| T1033 System Owner/User Discovery |
MalwareDRATzarus | DRATzarus can obtain a list of users from an infected machine. |
| T1033 System Owner/User Discovery |
MalwareRising Sun | Rising Sun can detect the username of the infected host. |
| T1033 System Owner/User Discovery |
MalwareChrommme | Chrommme can retrieve the username from a targeted system. |
| T1033 System Owner/User Discovery |
MalwareObliqueRAT | ObliqueRAT can check for blocklisted usernames on infected endpoints. |
| T1033 System Owner/User Discovery |
MalwareSocGholish | SocGholish can use `whoami` to obtain the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareFlagpro | Flagpro has been used to run the |
| T1033 System Owner/User Discovery |
MalwareXAgentOSX | XAgentOSX contains the getInfoOSX function to return the OS X version as well as the current user. |
| T1033 System Owner/User Discovery |
MalwareROKRAT | ROKRAT can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareDarkWatchman | DarkWatchman has collected the username from a victim machine. |
| T1033 System Owner/User Discovery |
MalwareDyre | Dyre has the ability to identify the users on a compromised host. |
| T1033 System Owner/User Discovery |
MalwarePlugX | PlugX has the ability to gather the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareReaver | Reaver collects the victim's username. |
| T1033 System Owner/User Discovery |
MalwareS-Type | S-Type has run tests to determine the privilege level of the compromised user. |
| T1033 System Owner/User Discovery |
MalwareRemsec | Remsec can obtain information about the current user. |
| T1033 System Owner/User Discovery |
MalwareExplosive | Explosive has collected the username from the infected host. |
| T1033 System Owner/User Discovery |
MalwareEpic | Epic collects the user name from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareClambling | Clambling can identify the username on a compromised host. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.