ATT&CKProcedure examples

Procedure examples

Real-world descriptions of how a group, tool or campaign used a technique.

Technique: T1087.002×

28 examples

TechniqueUsed byProcedure example
T1087.002
Domain Account
MalwareStuxnet

Stuxnet enumerates user accounts of the domain.

T1087.002
Domain Account
MalwarePOWRUNER

POWRUNER may collect user account information by running net user /domain or a series of other commands on a victim.

T1087.002
Domain Account
MalwareBankshot

Bankshot gathers domain and account names/information through process monitoring.

T1087.002
Domain Account
MalwareDUSTTRAP

DUSTTRAP can enumerate domain accounts.

T1087.002
Domain Account
MalwareRustyWater

RustyWater has gathered the domain membership of the victim machine’s user.

T1087.002
Domain Account
MalwareBlackCat

BlackCat can utilize `net use` commands to identify domain users.

T1087.002
Domain Account
MalwareIcedID

IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect.

T1087.002
Domain Account
MalwareSykipot

Sykipot may use net group "domain admins" /domain to display accounts in the "domain admins" permissions group and net localgroup "administrators" to list local system administrator group membership.

T1087.002
Domain Account
MalwareLatrodectus

Latrodectus can run `C:\Windows\System32\cmd.exe /c net group "Domain Admins" /domain` to identify domain administrator accounts.

T1087.002
Domain Account
MalwareBazar

Bazar has the ability to identify domain administrator accounts.

T1087.002
Domain Account
MalwareMgBot

MgBot includes modules for collecting information on Active Directory domain accounts.

T1087.002
Domain Account
MalwareCobalt Strike

Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group.

T1087.002
Domain Account
MalwareValak

Valak has the ability to enumerate domain admin accounts.

T1087.002
Domain Account
MalwareBoomBox

BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users.

T1087.002
Domain Account
MalwareLAMEHUG

LAMEHUG can use dsquery to enumerate domain user information.

T1087.002
Domain Account
MalwareIceApple

The IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server.

T1087.002
Domain Account
MalwareQilin

Qilin can use PowerShell cmdlets to enumerate domain users.

T1087.002
Domain Account
MalwareSoreFang

SoreFang can enumerate domain accounts via net.exe user /domain.

T1087.002
Domain Account
MalwareOSInfo

OSInfo enumerates local and domain users

T1087.002
Domain Account
ToolNet

Net commands used with the /domain flag can be used to gather information about and manipulate user accounts on the current domain.

T1087.002
Domain Account
ToolBloodHound

BloodHound can collect information about domain users, including identification of domain admin accounts.

T1087.002
Domain Account
ToolSILENTTRINITY

SILENTTRINITY can use `System.Security.AccessControl` namespaces to retrieve domain user information.

T1087.002
Domain Account
ToolEmpire

Empire can acquire local and domain user account information.

T1087.002
Domain Account
Tooldsquery

dsquery can be used to gather information on user accounts within a domain.

T1087.002
Domain Account
ToolPoshC2

PoshC2 can enumerate local and domain user account information.

T1087.002
Domain Account
ToolBrute Ratel C4

Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery.

T1087.002
Domain Account
ToolCrackMapExec

CrackMapExec can enumerate the domain user accounts on a targeted system.

T1087.002
Domain Account
ToolAdFind

AdFind can enumerate domain users.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.