Real-world descriptions of how a group, tool or campaign used a technique.
18 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1087.001 Local Account |
GroupAPT3 | APT3 has used a tool that can obtain info about local and global group users, power users, and administrators. |
| T1087.001 Local Account |
Groupadmin@338 | admin@338 actors used the following commands following exploitation of a machine with LOWBALL malware to enumerate user accounts: |
| T1087.001 Local Account |
GroupVolt Typhoon | Volt Typhoon has executed `net user` and `quser` to enumerate local account information. |
| T1087.001 Local Account |
GroupAPT41 | APT41 used built-in |
| T1087.001 Local Account |
GroupAPT32 | APT32 enumerated administrative users using the commands |
| T1087.001 Local Account |
GroupMoses Staff | Moses Staff has collected the administrator username from a compromised host. |
| T1087.001 Local Account |
GroupOilRig | OilRig has run |
| T1087.001 Local Account |
GroupKe3chang | Ke3chang performs account discovery using commands such as |
| T1087.001 Local Account |
GroupAPT1 | APT1 used the commands |
| T1087.001 Local Account |
GroupTurla | Turla has used |
| T1087.001 Local Account |
GroupPoseidon Group | Poseidon Group searches for administrator accounts on both the local victim machine and the network. |
| T1087.001 Local Account |
GroupRedCurl | RedCurl has collected information about local accounts. |
| T1087.001 Local Account |
GroupLotus Blossom | Lotus Blossom has used commands such as `net` to profile local system users. |
| T1087.001 Local Account |
GroupChimera | Chimera has used |
| T1087.001 Local Account |
GroupMedusa Group | Medusa Group has leveraged `net user` for account discovery. |
| T1087.001 Local Account |
GroupAPT42 | APT42 has used the PowerShell-based POWERPOST script to collect local account names from the victim machine. |
| T1087.001 Local Account |
GroupFox Kitten | Fox Kitten has accessed ntuser.dat and UserClass.dat on compromised hosts. |
| T1087.001 Local Account |
GroupThreat Group-3390 | Threat Group-3390 has used |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.