ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1087.001×

18 examples

TechniqueUsed byProcedure example
T1087.001
Local Account
GroupAPT3

APT3 has used a tool that can obtain info about local and global group users, power users, and administrators.

T1087.001
Local Account
Groupadmin@338

admin@338 actors used the following commands following exploitation of a machine with LOWBALL malware to enumerate user accounts: net user >> %temp%\download net user /domain >> %temp%\download

T1087.001
Local Account
GroupVolt Typhoon

Volt Typhoon has executed `net user` and `quser` to enumerate local account information.

T1087.001
Local Account
GroupAPT41

APT41 used built-in net commands to enumerate local administrator groups.

T1087.001
Local Account
GroupAPT32

APT32 enumerated administrative users using the commands net localgroup administrators.

T1087.001
Local Account
GroupMoses Staff

Moses Staff has collected the administrator username from a compromised host.

T1087.001
Local Account
GroupOilRig

OilRig has run net user, net user /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to get account listings on a victim.

T1087.001
Local Account
GroupKe3chang

Ke3chang performs account discovery using commands such as net localgroup administrators and net group "REDACTED" /domain on specific permissions groups.

T1087.001
Local Account
GroupAPT1

APT1 used the commands net localgroup,net user, and net group to find accounts on the system.

T1087.001
Local Account
GroupTurla

Turla has used net user to enumerate local accounts on the system.

T1087.001
Local Account
GroupPoseidon Group

Poseidon Group searches for administrator accounts on both the local victim machine and the network.

T1087.001
Local Account
GroupRedCurl

RedCurl has collected information about local accounts.

T1087.001
Local Account
GroupLotus Blossom

Lotus Blossom has used commands such as `net` to profile local system users.

T1087.001
Local Account
GroupChimera

Chimera has used net user for account discovery.

T1087.001
Local Account
GroupMedusa Group

Medusa Group has leveraged `net user` for account discovery.

T1087.001
Local Account
GroupAPT42

APT42 has used the PowerShell-based POWERPOST script to collect local account names from the victim machine.

T1087.001
Local Account
GroupFox Kitten

Fox Kitten has accessed ntuser.dat and UserClass.dat on compromised hosts.

T1087.001
Local Account
GroupThreat Group-3390

Threat Group-3390 has used net user to conduct internal discovery of systems.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.