Real-world descriptions of how a group, tool or campaign used a technique.
45 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1087.001 Local Account |
MalwareTrickBot | TrickBot collects the users of the system. |
| T1087.001 Local Account |
MalwarePikabot | Pikabot will retrieve the name of the user associated with the thread under which the malware is executing. |
| T1087.001 Local Account |
MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about users on remote hosts. |
| T1087.001 Local Account |
MalwareStuxnet | Stuxnet enumerates user accounts of the local host. |
| T1087.001 Local Account |
MalwareGeminiDuke | GeminiDuke collects information on local user accounts from the victim. |
| T1087.001 Local Account |
MalwareInvisibleFerret | InvisibleFerret has queried the victim device using Python scripts to obtain the User and Hostname. |
| T1087.001 Local Account |
MalwareBankshot | Bankshot gathers domain and account names/information through process monitoring. |
| T1087.001 Local Account |
MalwarePony | Pony has used the |
| T1087.001 Local Account |
MalwareHyperStack | HyperStack can enumerate all account names on a remote share. |
| T1087.001 Local Account |
MalwareDUSTTRAP | DUSTTRAP can enumerate local user accounts. |
| T1087.001 Local Account |
MalwareSystemBC | SystemBC has collected the Windows account username on the victim machine. |
| T1087.001 Local Account |
MalwareInvisiMole | InvisiMole has a command to list account information on the victim’s machine. |
| T1087.001 Local Account |
MalwareP.A.S. Webshell | P.A.S. Webshell can display the /etc/passwd file on a compromised host. |
| T1087.001 Local Account |
MalwareKazuar | Kazuar gathers information on local groups and members on the victim’s machine. |
| T1087.001 Local Account |
MalwareSHOTPUT | SHOTPUT has a command to retrieve information about connected users. |
| T1087.001 Local Account |
MalwarePUNCHBUGGY | PUNCHBUGGY can gather user names. |
| T1087.001 Local Account |
MalwareS-Type | S-Type has run the command `net user` on a victim. |
| T1087.001 Local Account |
MalwareRemsec | Remsec can obtain a list of users. |
| T1087.001 Local Account |
MalwareEpic | Epic gathers a list of all user accounts, privilege classes, and time of last logon. |
| T1087.001 Local Account |
MalwareElise | Elise executes |
| T1087.001 Local Account |
MalwareUSBferry | USBferry can use |
| T1087.001 Local Account |
MalwareSMOKEDHAM | SMOKEDHAM has used |
| T1087.001 Local Account |
MalwareRedLine Stealer | RedLine Stealer has collected account information from the victim’s machine. |
| T1087.001 Local Account |
MalwareBazar | Bazar can identify administrator accounts on an infected host. |
| T1087.001 Local Account |
MalwareRATANKBA | RATANKBA uses the |
| T1087.001 Local Account |
MalwareMgBot | MgBot includes modules for identifying local administrator accounts on victim systems. |
| T1087.001 Local Account |
MalwareValak | Valak has the ability to enumerate local admin accounts. |
| T1087.001 Local Account |
MalwareMilan | Milan has run `C:\Windows\system32\cmd.exe /c cmd /c dir c:\users\ /s 2>&1` to discover local accounts. |
| T1087.001 Local Account |
MalwareRaccoon Stealer | Raccoon Stealer checks the privileges of running processes to determine if the running user is equivalent to `NT Authority\System`. |
| T1087.001 Local Account |
MalwareKwampirs | Kwampirs collects a list of accounts with the command |
| T1087.001 Local Account |
MalwareMis-Type | Mis-Type may create a file containing the results of the command |
| T1087.001 Local Account |
MalwareQilin | Qilin can list all local users found on a targeted system. |
| T1087.001 Local Account |
MalwareSoreFang | SoreFang can collect usernames from the local system via |
| T1087.001 Local Account |
MalwareAgent Tesla | Agent Tesla can collect account information from the victim’s machine. |
| T1087.001 Local Account |
MalwarePOWERSTATS | POWERSTATS can retrieve usernames from compromised hosts. |
| T1087.001 Local Account |
MalwareComnie | Comnie uses the |
| T1087.001 Local Account |
MalwareOSInfo | OSInfo enumerates local and domain users |
| T1087.001 Local Account |
MalwareBitPaymer | BitPaymer can enumerate the sessions for each user logged onto the infected host. |
| T1087.001 Local Account |
ToolNet | Commands under |
| T1087.001 Local Account |
ToolBloodHound | BloodHound can identify users with local administrator rights. |
| T1087.001 Local Account |
ToolPowerSploit | PowerSploit's |
| T1087.001 Local Account |
ToolEmpire | Empire can acquire local and domain user account information. |
| T1087.001 Local Account |
ToolPoshC2 | PoshC2 can enumerate local and domain user account information. |
| T1087.001 Local Account |
ToolPupy | Pupy uses PowerView and Pywerview to perform discovery commands such as net user, net group, net local group, etc. |
| T1087.001 Local Account |
MalwareDuqu | The discovery modules used with Duqu can collect information on accounts and permissions. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.