Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwarePureCrypter | PureCrypter can retrieve the username from targeted machines. |
| T1033 System Owner/User Discovery |
MalwareNanHaiShu | NanHaiShu collects the username from the victim. |
| T1033 System Owner/User Discovery |
MalwareSVCReady | SVCReady can collect the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwareNGLite | NGLite will run the |
| T1033 System Owner/User Discovery |
MalwareSHARPSTATS | SHARPSTATS has the ability to identify the username on the compromised host. |
| T1033 System Owner/User Discovery |
MalwareCaterpillar WebShell | Caterpillar WebShell can obtain a list of user accounts from a victim's machine. |
| T1033 System Owner/User Discovery |
MalwareGazer | Gazer obtains the current user's security identifier. |
| T1033 System Owner/User Discovery |
MalwareLatrodectus | Latrodectus can discover the username of an infected host. |
| T1033 System Owner/User Discovery |
MalwareSaint Bot | Saint Bot can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareChaes | Chaes has collected the username and UID from the infected machine. |
| T1033 System Owner/User Discovery |
MalwareLODEINFO | LODEINFO can identify the associated username on targeted machines. |
| T1033 System Owner/User Discovery |
MalwareEVILNUM | EVILNUM can obtain the username from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareSMOKEDHAM | SMOKEDHAM has used |
| T1033 System Owner/User Discovery |
MalwareQUADAGENT | QUADAGENT gathers the victim username. |
| T1033 System Owner/User Discovery |
MalwareSys10 | Sys10 collects the account name of the logged-in user and sends it to the C2. |
| T1033 System Owner/User Discovery |
MalwareMetamorfo | Metamorfo has collected the username from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareTrojan.Karagany | Trojan.Karagany can gather information about the user on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareKONNI | KONNI can collect the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareT9000 | T9000 gathers and beacons the username of the logged in account during installation. It will also gather the username of running processes to determine if it is running as SYSTEM. |
| T1033 System Owner/User Discovery |
MalwareDnsSystem | DnsSystem can use the Windows user name to create a unique identification for infected users and systems. |
| T1033 System Owner/User Discovery |
MalwareBLUELIGHT | BLUELIGHT can collect the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareIxeshe | Ixeshe collects the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareMicropsia | Micropsia collects the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareRedLine Stealer | RedLine Stealer has obtained the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareRogueRobin | RogueRobin collects the victim’s username and whether that user is an admin. |
| T1033 System Owner/User Discovery |
MalwareLitePower | LitePower can determine if the current user has admin privileges. |
| T1033 System Owner/User Discovery |
MalwareSDBbot | SDBbot has the ability to identify the user on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareMosquito | Mosquito runs |
| T1033 System Owner/User Discovery |
MalwareRTM | RTM can obtain the victim username and permissions. |
| T1033 System Owner/User Discovery |
MalwareDerusbi | A Linux version of Derusbi checks if the victim user ID is anything other than zero (normally used for root), and the malware will not execute if it does not have root privileges. Derusbi also gathers the username of the victim. |
| T1033 System Owner/User Discovery |
MalwareSodaMaster | SodaMaster can identify the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareGrandoreiro | Grandoreiro can collect the username from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareWellMail | WellMail can identify the current username on the victim system. |
| T1033 System Owner/User Discovery |
MalwareLiteDuke | LiteDuke can enumerate the account name on a targeted system. |
| T1033 System Owner/User Discovery |
MalwareZxxZ | ZxxZ can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareWINDSHIELD | WINDSHIELD can gather the victim user name. |
| T1033 System Owner/User Discovery |
MalwareBazar | Bazar can identify the username of the infected user. |
| T1033 System Owner/User Discovery |
MalwareRATANKBA | RATANKBA runs the |
| T1033 System Owner/User Discovery |
MalwareXLoader | XLoader can identify the username from a victim machine. |
| T1033 System Owner/User Discovery |
MalwareMoonWind | MoonWind obtains the victim username. |
| T1033 System Owner/User Discovery |
MalwareHiddenFace | HiddenFace can collect the username associated with the compromised host. |
| T1033 System Owner/User Discovery |
MalwareCryptoistic | Cryptoistic can gather data on the user of a compromised host. |
| T1033 System Owner/User Discovery |
MalwareMgBot | MgBot includes modules for identifying local users and administrators on victim machines. |
| T1033 System Owner/User Discovery |
MalwareZebrocy | Zebrocy gets the username from the system. |
| T1033 System Owner/User Discovery |
MalwareSpeakUp | SpeakUp uses the |
| T1033 System Owner/User Discovery |
MalwareSUNBURST | SUNBURST collected the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareHotCroissant | HotCroissant has the ability to collect the username on the infected host. |
| T1033 System Owner/User Discovery |
MalwareServHelper | ServHelper will attempt to enumerate the username of the victim. |
| T1033 System Owner/User Discovery |
MalwareUnknown Logger | Unknown Logger can obtain information about the victim usernames. |
| T1033 System Owner/User Discovery |
MalwareValak | Valak can gather information regarding the user. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.