Real-world descriptions of how a group, tool or campaign used a technique.
196 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareEgregor | Egregor has used tools to gather information about users. |
| T1033 System Owner/User Discovery |
MalwarePoetRAT | PoetRAT sent username, computer name, and the previously generated UUID in reply to a "who" command from C2. |
| T1033 System Owner/User Discovery |
MalwareFELIXROOT | FELIXROOT collects the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareZxShell | ZxShell can collect the owner and organization information from the target workstation. |
| T1033 System Owner/User Discovery |
MalwareNDiskMonitor | NDiskMonitor obtains the victim username and encrypts the information to send over its C2 channel. |
| T1033 System Owner/User Discovery |
MalwareBabyShark | BabyShark has executed the |
| T1033 System Owner/User Discovery |
MalwareCannon | Cannon can gather the username from the system. |
| T1033 System Owner/User Discovery |
MalwareCreepySnail | CreepySnail can execute `getUsername` on compromised systems. |
| T1033 System Owner/User Discovery |
MalwarenjRAT | njRAT enumerates the current user during the initial infection. |
| T1033 System Owner/User Discovery |
MalwareJPIN | JPIN can obtain the victim user name. |
| T1033 System Owner/User Discovery |
MalwaremetaMain | metaMain can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareSideTwist | SideTwist can collect the username on a targeted system. |
| T1033 System Owner/User Discovery |
MalwareMechaFlounder | MechaFlounder has the ability to identify the username and hostname on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareMis-Type | Mis-Type runs tests to determine the privilege level of the compromised user. |
| T1033 System Owner/User Discovery |
MalwareLunarWeb | LunarWeb can collect user information from the targeted host. |
| T1033 System Owner/User Discovery |
MalwareOctopus | Octopus can collect the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareSTARWHALE | STARWHALE can gather the username from an infected host. |
| T1033 System Owner/User Discovery |
MalwareMirageFox | MirageFox can gather the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareDownPaper | DownPaper collects the victim username and sends it to the C2 server. |
| T1033 System Owner/User Discovery |
MalwareAgent Tesla | Agent Tesla can collect the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwarePOWERSTATS | POWERSTATS has the ability to identify the username on the compromised host. |
| T1033 System Owner/User Discovery |
MalwareGoopy | Goopy has the ability to enumerate the infected system's user name. |
| T1033 System Owner/User Discovery |
MalwareShadowPad | ShadowPad has collected the username of the victim system. |
| T1033 System Owner/User Discovery |
MalwareQakBot | QakBot can identify the user name on a compromised system. |
| T1033 System Owner/User Discovery |
MalwareGelsemium | Gelsemium has the ability to distinguish between a standard user and an administrator on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareKomplex | The OsInfo function in Komplex collects the current running username. |
| T1033 System Owner/User Discovery |
MalwareDenis | Denis enumerates and collects the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareLizar | Lizar can collect the username from the system. |
| T1033 System Owner/User Discovery |
MalwareAzorult | Azorult can collect the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareUPPERCUT | UPPERCUT has the capability to collect the current logged on user’s username from a machine. |
| T1033 System Owner/User Discovery |
MalwareStrifeWater | StrifeWater can collect the user name from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareSLOTHFULMEDIA | SLOTHFULMEDIA has collected the username from a victim machine. |
| T1033 System Owner/User Discovery |
MalwareXORIndex Loader | XORIndex Loader has collected the username from the victim host. |
| T1033 System Owner/User Discovery |
MalwareSmall Sieve | Small Sieve can obtain the id of a logged in user. |
| T1033 System Owner/User Discovery |
ToolBloodHound | BloodHound can collect information on user sessions. |
| T1033 System Owner/User Discovery |
ToolSILENTTRINITY | SILENTTRINITY can gather a list of logged on users. |
| T1033 System Owner/User Discovery |
ToolEmpire | Empire can enumerate the username on targeted hosts. |
| T1033 System Owner/User Discovery |
ToolAsyncRAT | AsyncRAT can check if the current user of a compromised system is an administrator. |
| T1033 System Owner/User Discovery |
ToolRemcos | Remcos can enumerate the username on targeted hosts. |
| T1033 System Owner/User Discovery |
ToolNBTscan | NBTscan can list active users on the system. |
| T1033 System Owner/User Discovery |
ToolKoadic | Koadic can identify logged in users across the domain and views user sessions. |
| T1033 System Owner/User Discovery |
ToolPupy | Pupy can enumerate local information for Linux hosts and find currently logged on users for Windows hosts. |
| T1033 System Owner/User Discovery |
ToolQuasarRAT | QuasarRAT can enumerate the username and account type. |
| T1033 System Owner/User Discovery |
MalwareTeamPCP Cloud Stealer | TeamPCP Cloud Stealer can use `whoami` on self-hosted runners to identify the current user. |
| T1033 System Owner/User Discovery |
MalwareMini Shai-Hulud | Mini Shai-Hulud has leveraged commands such as `whoami` to identify the system owner. |
| T1033 System Owner/User Discovery |
MalwareCanisterWorm | CanisterWorm has parsed the /var/log/auth.log and /var/log/secure files for usernames. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.