ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1087.002×

29 examples

TechniqueUsed byProcedure example
T1087.002
Domain Account
GroupBlackByte

BlackByte has used tools such as AdFind to identify and enumerate domain accounts.

T1087.002
Domain Account
GroupVolt Typhoon

Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery.

T1087.002
Domain Account
GroupAPT41

APT41 used built-in net commands to enumerate domain administrator users.

T1087.002
Domain Account
GroupDragonfly

Dragonfly has used batch scripts to enumerate users on a victim domain controller.

T1087.002
Domain Account
GroupmenuPass

menuPass has used the Microsoft administration tool csvde.exe to export Active Directory data.

T1087.002
Domain Account
GroupMuddyWater

MuddyWater has used cmd.exe net user /domain to enumerate domain users.

T1087.002
Domain Account
GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

T1087.002
Domain Account
GroupStorm-1811

Storm-1811 has performed domain account enumeration during intrusions.

T1087.002
Domain Account
GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information.

T1087.002
Domain Account
GroupSandworm Team

Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about usernames listed in AD.

T1087.002
Domain Account
GroupMustang Panda

Mustang Panda has utilized AdFind to identify domain users.

T1087.002
Domain Account
GroupScattered Spider

Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment.

T1087.002
Domain Account
GroupOilRig

OilRig has run net user, net user /domain, net group “domain admins” /domain, and net group “Exchange Trusted Subsystem” /domain to get account listings on a victim.

T1087.002
Domain Account
GroupKe3chang

Ke3chang performs account discovery using commands such as net localgroup administrators and net group "REDACTED" /domain on specific permissions groups.

T1087.002
Domain Account
GroupTurla

Turla has used net user /domain to enumerate domain accounts.

T1087.002
Domain Account
GroupStorm-0501

Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts.

T1087.002
Domain Account
GroupPoseidon Group

Poseidon Group searches for administrator accounts on both the local victim machine and the network.

T1087.002
Domain Account
GroupRedCurl

RedCurl has collected information about domain accounts using SysInternal’s AdExplorer functionality .

T1087.002
Domain Account
GroupLotus Blossom

Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries.

T1087.002
Domain Account
GroupChimera

Chimera has has used net user /dom and net user Administrator to enumerate domain accounts including administrator accounts.

T1087.002
Domain Account
GroupMirrorFace

MirrorFace has used native Windows tools to obtain domain user information.

T1087.002
Domain Account
GroupBRONZE BUTLER

BRONZE BUTLER has used net user /domain to identify account information.

T1087.002
Domain Account
GroupToddyCat

ToddyCat has run `net user %USER% /dom` for account discovery.

T1087.002
Domain Account
GroupFox Kitten

Fox Kitten has used the Softerra LDAP browser to browse documentation on service accounts.

T1087.002
Domain Account
GroupINC Ransom

INC Ransom has scanned for domain admin accounts in compromised environments.

T1087.002
Domain Account
GroupLAPSUS$

LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network.

T1087.002
Domain Account
GroupWizard Spider

Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data.

T1087.002
Domain Account
GroupVOID MANTICORE

VOID MANTICORE has utilized ADRecon to enumerate the active directory environment.

T1087.002
Domain Account
GroupFIN13

FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.