ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1033×

196 examples

TechniqueUsed byProcedure example
T1033
System Owner/User Discovery
MalwareEgregor

Egregor has used tools to gather information about users.

T1033
System Owner/User Discovery
MalwarePoetRAT

PoetRAT sent username, computer name, and the previously generated UUID in reply to a "who" command from C2.

T1033
System Owner/User Discovery
MalwareFELIXROOT

FELIXROOT collects the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareZxShell

ZxShell can collect the owner and organization information from the target workstation.

T1033
System Owner/User Discovery
MalwareNDiskMonitor

NDiskMonitor obtains the victim username and encrypts the information to send over its C2 channel.

T1033
System Owner/User Discovery
MalwareBabyShark

BabyShark has executed the whoami command.

T1033
System Owner/User Discovery
MalwareCannon

Cannon can gather the username from the system.

T1033
System Owner/User Discovery
MalwareCreepySnail

CreepySnail can execute `getUsername` on compromised systems.

T1033
System Owner/User Discovery
MalwarenjRAT

njRAT enumerates the current user during the initial infection.

T1033
System Owner/User Discovery
MalwareJPIN

JPIN can obtain the victim user name.

T1033
System Owner/User Discovery
MalwaremetaMain

metaMain can collect the username from a compromised host.

T1033
System Owner/User Discovery
MalwareSideTwist

SideTwist can collect the username on a targeted system.

T1033
System Owner/User Discovery
MalwareMechaFlounder

MechaFlounder has the ability to identify the username and hostname on a compromised host.

T1033
System Owner/User Discovery
MalwareMis-Type

Mis-Type runs tests to determine the privilege level of the compromised user.

T1033
System Owner/User Discovery
MalwareLunarWeb

LunarWeb can collect user information from the targeted host.

T1033
System Owner/User Discovery
MalwareOctopus

Octopus can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareSTARWHALE

STARWHALE can gather the username from an infected host.

T1033
System Owner/User Discovery
MalwareMirageFox

MirageFox can gather the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareDownPaper

DownPaper collects the victim username and sends it to the C2 server.

T1033
System Owner/User Discovery
MalwareAgent Tesla

Agent Tesla can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwarePOWERSTATS

POWERSTATS has the ability to identify the username on the compromised host.

T1033
System Owner/User Discovery
MalwareGoopy

Goopy has the ability to enumerate the infected system's user name.

T1033
System Owner/User Discovery
MalwareShadowPad

ShadowPad has collected the username of the victim system.

T1033
System Owner/User Discovery
MalwareQakBot

QakBot can identify the user name on a compromised system.

T1033
System Owner/User Discovery
MalwareGelsemium

Gelsemium has the ability to distinguish between a standard user and an administrator on a compromised host.

T1033
System Owner/User Discovery
MalwareKomplex

The OsInfo function in Komplex collects the current running username.

T1033
System Owner/User Discovery
MalwareDenis

Denis enumerates and collects the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareLizar

Lizar can collect the username from the system.

T1033
System Owner/User Discovery
MalwareAzorult

Azorult can collect the username from the victim’s machine.

T1033
System Owner/User Discovery
MalwareUPPERCUT

UPPERCUT has the capability to collect the current logged on user’s username from a machine.

T1033
System Owner/User Discovery
MalwareStrifeWater

StrifeWater can collect the user name from the victim's machine.

T1033
System Owner/User Discovery
MalwareSLOTHFULMEDIA

SLOTHFULMEDIA has collected the username from a victim machine.

T1033
System Owner/User Discovery
MalwareXORIndex Loader

XORIndex Loader has collected the username from the victim host.

T1033
System Owner/User Discovery
MalwareSmall Sieve

Small Sieve can obtain the id of a logged in user.

T1033
System Owner/User Discovery
ToolBloodHound

BloodHound can collect information on user sessions.

T1033
System Owner/User Discovery
ToolSILENTTRINITY

SILENTTRINITY can gather a list of logged on users.

T1033
System Owner/User Discovery
ToolEmpire

Empire can enumerate the username on targeted hosts.

T1033
System Owner/User Discovery
ToolAsyncRAT

AsyncRAT can check if the current user of a compromised system is an administrator.

T1033
System Owner/User Discovery
ToolRemcos

Remcos can enumerate the username on targeted hosts.

T1033
System Owner/User Discovery
ToolNBTscan

NBTscan can list active users on the system.

T1033
System Owner/User Discovery
ToolKoadic

Koadic can identify logged in users across the domain and views user sessions.

T1033
System Owner/User Discovery
ToolPupy

Pupy can enumerate local information for Linux hosts and find currently logged on users for Windows hosts.

T1033
System Owner/User Discovery
ToolQuasarRAT

QuasarRAT can enumerate the username and account type.

T1033
System Owner/User Discovery
MalwareTeamPCP Cloud Stealer

TeamPCP Cloud Stealer can use `whoami` on self-hosted runners to identify the current user.

T1033
System Owner/User Discovery
MalwareMini Shai-Hulud

Mini Shai-Hulud has leveraged commands such as `whoami` to identify the system owner.

T1033
System Owner/User Discovery
MalwareCanisterWorm

CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for usernames.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.