Real-world descriptions of how a group, tool or campaign used a technique.
17136 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
MalwareRedLine Stealer | RedLine Stealer has obtained the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareRogueRobin | RogueRobin collects the victim’s username and whether that user is an admin. |
| T1033 System Owner/User Discovery |
MalwareLitePower | LitePower can determine if the current user has admin privileges. |
| T1033 System Owner/User Discovery |
MalwareSDBbot | SDBbot has the ability to identify the user on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareMosquito | Mosquito runs |
| T1033 System Owner/User Discovery |
MalwareRTM | RTM can obtain the victim username and permissions. |
| T1033 System Owner/User Discovery |
MalwareDerusbi | A Linux version of Derusbi checks if the victim user ID is anything other than zero (normally used for root), and the malware will not execute if it does not have root privileges. Derusbi also gathers the username of the victim. |
| T1033 System Owner/User Discovery |
MalwareSodaMaster | SodaMaster can identify the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareGrandoreiro | Grandoreiro can collect the username from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareWellMail | WellMail can identify the current username on the victim system. |
| T1033 System Owner/User Discovery |
MalwareLiteDuke | LiteDuke can enumerate the account name on a targeted system. |
| T1033 System Owner/User Discovery |
MalwareZxxZ | ZxxZ can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareWINDSHIELD | WINDSHIELD can gather the victim user name. |
| T1033 System Owner/User Discovery |
MalwareBazar | Bazar can identify the username of the infected user. |
| T1033 System Owner/User Discovery |
MalwareRATANKBA | RATANKBA runs the |
| T1033 System Owner/User Discovery |
MalwareXLoader | XLoader can identify the username from a victim machine. |
| T1033 System Owner/User Discovery |
MalwareMoonWind | MoonWind obtains the victim username. |
| T1033 System Owner/User Discovery |
MalwareHiddenFace | HiddenFace can collect the username associated with the compromised host. |
| T1033 System Owner/User Discovery |
MalwareCryptoistic | Cryptoistic can gather data on the user of a compromised host. |
| T1033 System Owner/User Discovery |
MalwareMgBot | MgBot includes modules for identifying local users and administrators on victim machines. |
| T1033 System Owner/User Discovery |
MalwareZebrocy | Zebrocy gets the username from the system. |
| T1033 System Owner/User Discovery |
MalwareSpeakUp | SpeakUp uses the |
| T1033 System Owner/User Discovery |
MalwareSUNBURST | SUNBURST collected the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareHotCroissant | HotCroissant has the ability to collect the username on the infected host. |
| T1033 System Owner/User Discovery |
MalwareServHelper | ServHelper will attempt to enumerate the username of the victim. |
| T1033 System Owner/User Discovery |
MalwareUnknown Logger | Unknown Logger can obtain information about the victim usernames. |
| T1033 System Owner/User Discovery |
MalwareValak | Valak can gather information regarding the user. |
| T1033 System Owner/User Discovery |
MalwareMilan | Milan can identify users registered to a targeted machine. |
| T1033 System Owner/User Discovery |
MalwareOilBooster | OilBooster can identify the compromised system's username which is then used as part of a unique identifier. |
| T1033 System Owner/User Discovery |
MalwareRaccoon Stealer | Raccoon Stealer gathers information on the infected system owner and user. |
| T1033 System Owner/User Discovery |
MalwareCardinal RAT | Cardinal RAT can collect the username from a victim machine. |
| T1033 System Owner/User Discovery |
MalwareBISCUIT | BISCUIT has a command to gather the username from the system. |
| T1033 System Owner/User Discovery |
MalwareGold Dragon | Gold Dragon collects the endpoint victim's username and uses it as a basis for downloading additional components from the C2 server. |
| T1033 System Owner/User Discovery |
MalwareRGDoor | RGDoor executes the |
| T1033 System Owner/User Discovery |
MalwareRevenge RAT | Revenge RAT gathers the username from the system. |
| T1033 System Owner/User Discovery |
MalwareMacMa | MacMa can collect the username from the compromised machine. |
| T1033 System Owner/User Discovery |
MalwareFunnyDream | FunnyDream has the ability to gather user information from the targeted system using `whoami/upn&whoami/fqdn&whoami/logonid&whoami/all`. |
| T1033 System Owner/User Discovery |
MalwareMore_eggs | More_eggs has the capability to gather the username from the victim's machine. |
| T1033 System Owner/User Discovery |
MalwareSysUpdate | SysUpdate can collect the username from a compromised host. |
| T1033 System Owner/User Discovery |
MalwareKwampirs | Kwampirs collects registered owner details by using the commands |
| T1033 System Owner/User Discovery |
MalwareBoomBox | BoomBox can enumerate the username on a compromised host. |
| T1033 System Owner/User Discovery |
MalwareLAMEHUG | LAMEHUG can use `whoami` to enumerate the system user. |
| T1033 System Owner/User Discovery |
MalwareMango | Mango can collect the user name from a compromised system which is used to create a unique victim identifier. |
| T1033 System Owner/User Discovery |
MalwareGrimAgent | GrimAgent can identify the user id on a target machine. |
| T1033 System Owner/User Discovery |
MalwareLokibot | Lokibot has the ability to discover the username on the infected host. |
| T1033 System Owner/User Discovery |
MalwareEgregor | Egregor has used tools to gather information about users. |
| T1033 System Owner/User Discovery |
MalwarePoetRAT | PoetRAT sent username, computer name, and the previously generated UUID in reply to a "who" command from C2. |
| T1033 System Owner/User Discovery |
MalwareFELIXROOT | FELIXROOT collects the username from the victim’s machine. |
| T1033 System Owner/User Discovery |
MalwareZxShell | ZxShell can collect the owner and organization information from the target workstation. |
| T1033 System Owner/User Discovery |
MalwareNDiskMonitor | NDiskMonitor obtains the victim username and encrypts the information to send over its C2 channel. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.