ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1087.001×

45 examples

TechniqueUsed byProcedure example
T1087.001
Local Account
MalwareTrickBot

TrickBot collects the users of the system.

T1087.001
Local Account
MalwarePikabot

Pikabot will retrieve the name of the user associated with the thread under which the malware is executing.

T1087.001
Local Account
MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about users on remote hosts.

T1087.001
Local Account
MalwareStuxnet

Stuxnet enumerates user accounts of the local host.

T1087.001
Local Account
MalwareGeminiDuke

GeminiDuke collects information on local user accounts from the victim.

T1087.001
Local Account
MalwareInvisibleFerret

InvisibleFerret has queried the victim device using Python scripts to obtain the User and Hostname.

T1087.001
Local Account
MalwareBankshot

Bankshot gathers domain and account names/information through process monitoring.

T1087.001
Local Account
MalwarePony

Pony has used the NetUserEnum function to enumerate local accounts.

T1087.001
Local Account
MalwareHyperStack

HyperStack can enumerate all account names on a remote share.

T1087.001
Local Account
MalwareDUSTTRAP

DUSTTRAP can enumerate local user accounts.

T1087.001
Local Account
MalwareSystemBC

SystemBC has collected the Windows account username on the victim machine.

T1087.001
Local Account
MalwareInvisiMole

InvisiMole has a command to list account information on the victim’s machine.

T1087.001
Local Account
MalwareP.A.S. Webshell

P.A.S. Webshell can display the /etc/passwd file on a compromised host.

T1087.001
Local Account
MalwareKazuar

Kazuar gathers information on local groups and members on the victim’s machine.

T1087.001
Local Account
MalwareSHOTPUT

SHOTPUT has a command to retrieve information about connected users.

T1087.001
Local Account
MalwarePUNCHBUGGY

PUNCHBUGGY can gather user names.

T1087.001
Local Account
MalwareS-Type

S-Type has run the command `net user` on a victim.

T1087.001
Local Account
MalwareRemsec

Remsec can obtain a list of users.

T1087.001
Local Account
MalwareEpic

Epic gathers a list of all user accounts, privilege classes, and time of last logon.

T1087.001
Local Account
MalwareElise

Elise executes net user after initial communication is made to the remote server.

T1087.001
Local Account
MalwareUSBferry

USBferry can use net user to gather information about local accounts.

T1087.001
Local Account
MalwareSMOKEDHAM

SMOKEDHAM has used net.exe user and net.exe users to enumerate local accounts on a compromised host.

T1087.001
Local Account
MalwareRedLine Stealer

RedLine Stealer has collected account information from the victim’s machine.

T1087.001
Local Account
MalwareBazar

Bazar can identify administrator accounts on an infected host.

T1087.001
Local Account
MalwareRATANKBA

RATANKBA uses the net user command.

T1087.001
Local Account
MalwareMgBot

MgBot includes modules for identifying local administrator accounts on victim systems.

T1087.001
Local Account
MalwareValak

Valak has the ability to enumerate local admin accounts.

T1087.001
Local Account
MalwareMilan

Milan has run `C:\Windows\system32\cmd.exe /c cmd /c dir c:\users\ /s 2>&1` to discover local accounts.

T1087.001
Local Account
MalwareRaccoon Stealer

Raccoon Stealer checks the privileges of running processes to determine if the running user is equivalent to `NT Authority\System`.

T1087.001
Local Account
MalwareKwampirs

Kwampirs collects a list of accounts with the command net users.

T1087.001
Local Account
MalwareMis-Type

Mis-Type may create a file containing the results of the command cmd.exe /c net user {Username}.

T1087.001
Local Account
MalwareQilin

Qilin can list all local users found on a targeted system.

T1087.001
Local Account
MalwareSoreFang

SoreFang can collect usernames from the local system via net.exe user.

T1087.001
Local Account
MalwareAgent Tesla

Agent Tesla can collect account information from the victim’s machine.

T1087.001
Local Account
MalwarePOWERSTATS

POWERSTATS can retrieve usernames from compromised hosts.

T1087.001
Local Account
MalwareComnie

Comnie uses the net user command.

T1087.001
Local Account
MalwareOSInfo

OSInfo enumerates local and domain users

T1087.001
Local Account
MalwareBitPaymer

BitPaymer can enumerate the sessions for each user logged onto the infected host.

T1087.001
Local Account
ToolNet

Commands under net user can be used in Net to gather information about and manipulate user accounts.

T1087.001
Local Account
ToolBloodHound

BloodHound can identify users with local administrator rights.

T1087.001
Local Account
ToolPowerSploit

PowerSploit's Get-ProcessTokenGroup Privesc-PowerUp module can enumerate all SIDs associated with its current token.

T1087.001
Local Account
ToolEmpire

Empire can acquire local and domain user account information.

T1087.001
Local Account
ToolPoshC2

PoshC2 can enumerate local and domain user account information.

T1087.001
Local Account
ToolPupy

Pupy uses PowerView and Pywerview to perform discovery commands such as net user, net group, net local group, etc.

T1087.001
Local Account
MalwareDuqu

The discovery modules used with Duqu can collect information on accounts and permissions.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.