Real-world descriptions of how a group, tool or campaign used a technique.
11362 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareMilan | Milan can identify users registered to a targeted machine. |
| T1033 System Owner/User Discovery |
MalwareOilBooster | OilBooster can identify the compromised system's username which is then used as part of a unique identifier. |
| T1033 System Owner/User Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers information on the infected system owner and user. |
| T1033 System Owner/User Discovery |
MalwareCardinal RAT | Cardinal RAT can collect the username from a victim machine. |
| T1033 System Owner/User Discovery |
MalwareBISCUIT | BISCUIT has a command to gather the username from the system. |
| T1033 System Owner/User Discovery |
MalwareGold Dragon | Gold Dragon collects the endpoint victim's username and uses it as a basis for downloading additional components from the C2 server. |
| T1033 System Owner/User Discovery |
MalwareRGDoor | RGDoor executes the |
| T1033 System Owner/User Discovery |
MalwareRevenge RAT | Revenge RAT gathers the username from the system. |
| T1033 System Owner/User Discovery |
MalwareMacMa | MacMa can collect the username from the compromised machine. |
| T1033 System Owner/User Discovery |
MalwareFunnyDream | FunnyDream has the ability to gather user information from the targeted system using `whoami/upn&whoami/fqdn&whoami/logonid&whoami/all`. |
| T1033 System Owner/User Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the username from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareSysUpdate | SysUpdate can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareKwampirs | Kwampirs collects registered owner details by using the commands |
| T1033 System Owner/User Discovery |
MalwareBoomBox | BoomBox can enumerate the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareLAMEHUG | LAMEHUG can use `whoami` to enumerate the system user. |
| T1033 System Owner/User Discovery |
MalwareMango | Mango can collect the user name from a compromised system which is used to create a unique victim identifier. |
| T1033 System Owner/User Discovery |
MalwareGrimAgent | GrimAgent can identify the user id on a target machine. |
| T1033 System Owner/User Discovery |
MalwareLokibot | Lokibot has the ability to discover the username on the infected host. |
| T1033 System Owner/User Discovery |
MalwareEgregor | Egregor has used tools to gather information about users. |
| T1033 System Owner/User Discovery |
MalwarePoetRAT | PoetRAT sent username, computer name, and the previously generated UUID in reply to a "who" command from C2. |
| T1033 System Owner/User Discovery |
MalwareFELIXROOT | FELIXROOT collects the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareZxShell | ZxShell can collect the owner and organization information from the target workstation. |
| T1033 System Owner/User Discovery |
MalwareNDiskMonitor | NDiskMonitor obtains the victim username and encrypts the information to send over its C2 channel. |
| T1033 System Owner/User Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1033 System Owner/User Discovery |
MalwareCannon | Cannon can gather the username from the system. |
| T1033 System Owner/User Discovery |
MalwareCreepySnail | CreepySnail can execute `getUsername` on compromised systems. |
| T1033 System Owner/User Discovery |
MalwarenjRAT | njRAT enumerates the current user during the initial infection. |
| T1033 System Owner/User Discovery |
MalwareJPIN | JPIN can obtain the victim user name. |
| T1033 System Owner/User Discovery |
MalwaremetaMain | metaMain can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareSideTwist | SideTwist can collect the username on a targeted system. |
| T1033 System Owner/User Discovery |
MalwareMechaFlounder | MechaFlounder has the ability to identify the username and hostname on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareMis-Type | Mis-Type runs tests to determine the privilege level of the compromised user. |
| T1033 System Owner/User Discovery |
MalwareLunarWeb | LunarWeb can collect user information from the targeted host. |
| T1033 System Owner/User Discovery |
MalwareOctopus | Octopus can collect the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareSTARWHALE | STARWHALE can gather the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwareMirageFox | MirageFox can gather the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareDownPaper | DownPaper collects the victim username and sends it to the C2 server. |
| T1033 System Owner/User Discovery |
MalwareAgent Tesla | Agent Tesla can collect the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwarePOWERSTATS | POWERSTATS has the ability to identify the username on the compromised host. |
| T1033 System Owner/User Discovery |
MalwareGoopy | Goopy has the ability to enumerate the infected system's user name. |
| T1033 System Owner/User Discovery |
MalwareShadowPad | ShadowPad has collected the username of the victim system. |
| T1033 System Owner/User Discovery |
MalwareQakBot | QakBot can identify the user name on a compromised system. |
| T1033 System Owner/User Discovery |
MalwareGelsemium | Gelsemium has the ability to distinguish between a standard user and an administrator on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareKomplex | The OsInfo function in Komplex collects the current running username. |
| T1033 System Owner/User Discovery |
MalwareDenis | Denis enumerates and collects the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareLizar | Lizar can collect the username from the system. |
| T1033 System Owner/User Discovery |
MalwareAzorult | Azorult can collect the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to collect the current logged on user’s username from a machine. |
| T1033 System Owner/User Discovery |
MalwareStrifeWater | StrifeWater can collect the user name from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has collected the username from a victim machine. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.