Real-world descriptions of how a group, tool or campaign used a technique.
29 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1087.002 Domain Account |
GroupBlackByte | BlackByte has used tools such as AdFind to identify and enumerate domain accounts. |
| T1087.002 Domain Account |
GroupVolt Typhoon | Volt Typhoon has run `net group /dom` and `net group "Domain Admins" /dom` in compromised environments for account discovery. |
| T1087.002 Domain Account |
GroupAPT41 | APT41 used built-in |
| T1087.002 Domain Account |
GroupDragonfly | Dragonfly has used batch scripts to enumerate users on a victim domain controller. |
| T1087.002 Domain Account |
GroupmenuPass | menuPass has used the Microsoft administration tool csvde.exe to export Active Directory data. |
| T1087.002 Domain Account |
GroupMuddyWater | MuddyWater has used |
| T1087.002 Domain Account |
GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| T1087.002 Domain Account |
GroupStorm-1811 | Storm-1811 has performed domain account enumeration during intrusions. |
| T1087.002 Domain Account |
GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information. |
| T1087.002 Domain Account |
GroupSandworm Team | Sandworm Team has used a tool to query Active Directory using LDAP, discovering information about usernames listed in AD. |
| T1087.002 Domain Account |
GroupMustang Panda | Mustang Panda has utilized AdFind to identify domain users. |
| T1087.002 Domain Account |
GroupScattered Spider | Scattered Spider has enumerated legitimate domain accounts which are used in the targeted environment. |
| T1087.002 Domain Account |
GroupOilRig | OilRig has run |
| T1087.002 Domain Account |
GroupKe3chang | Ke3chang performs account discovery using commands such as |
| T1087.002 Domain Account |
GroupTurla | Turla has used |
| T1087.002 Domain Account |
GroupStorm-0501 | Storm-0501 has utilized an obfuscated version of the Active Directory reconnaissance tool ADRecon.ps1 (obfs.ps1 or recon.ps1) to discover domain accounts. |
| T1087.002 Domain Account |
GroupPoseidon Group | Poseidon Group searches for administrator accounts on both the local victim machine and the network. |
| T1087.002 Domain Account |
GroupRedCurl | RedCurl has collected information about domain accounts using SysInternal’s AdExplorer functionality . |
| T1087.002 Domain Account |
GroupLotus Blossom | Lotus Blossom has used `net` commands and tools such as AdFind to profile domain accounts associated with victim machines and make Active Directory queries. |
| T1087.002 Domain Account |
GroupChimera | Chimera has has used |
| T1087.002 Domain Account |
GroupMirrorFace | MirrorFace has used native Windows tools to obtain domain user information. |
| T1087.002 Domain Account |
GroupBRONZE BUTLER | BRONZE BUTLER has used |
| T1087.002 Domain Account |
GroupToddyCat | ToddyCat has run `net user %USER% /dom` for account discovery. |
| T1087.002 Domain Account |
GroupFox Kitten | Fox Kitten has used the Softerra LDAP browser to browse documentation on service accounts. |
| T1087.002 Domain Account |
GroupINC Ransom | INC Ransom has scanned for domain admin accounts in compromised environments. |
| T1087.002 Domain Account |
GroupLAPSUS$ | LAPSUS$ has used the AD Explorer tool to enumerate users on a victim's network. |
| T1087.002 Domain Account |
GroupWizard Spider | Wizard Spider has identified domain admins through the use of `net group "Domain admins" /DOMAIN`. Wizard Spider has also leveraged the PowerShell cmdlet `Get-ADComputer` to collect account names from Active Directory data. |
| T1087.002 Domain Account |
GroupVOID MANTICORE | VOID MANTICORE has utilized ADRecon to enumerate the active directory environment. |
| T1087.002 Domain Account |
GroupFIN13 | FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.