Real-world descriptions of how a group, tool or campaign used a technique.
28 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1087.002 Domain Account |
MalwareStuxnet | Stuxnet enumerates user accounts of the domain. |
| T1087.002 Domain Account |
MalwarePOWRUNER | POWRUNER may collect user account information by running |
| T1087.002 Domain Account |
MalwareBankshot | Bankshot gathers domain and account names/information through process monitoring. |
| T1087.002 Domain Account |
MalwareDUSTTRAP | DUSTTRAP can enumerate domain accounts. |
| T1087.002 Domain Account |
MalwareRustyWater | RustyWater has gathered the domain membership of the victim machine’s user. |
| T1087.002 Domain Account |
MalwareBlackCat | BlackCat can utilize `net use` commands to identify domain users. |
| T1087.002 Domain Account |
MalwareIcedID | IcedID can query LDAP and can use built-in `net` commands to identify additional users on the network to infect. |
| T1087.002 Domain Account |
MalwareSykipot | Sykipot may use |
| T1087.002 Domain Account |
MalwareLatrodectus | Latrodectus can run `C:\Windows\System32\cmd.exe /c net group "Domain Admins" /domain` to identify domain administrator accounts. |
| T1087.002 Domain Account |
MalwareBazar | Bazar has the ability to identify domain administrator accounts. |
| T1087.002 Domain Account |
MalwareMgBot | MgBot includes modules for collecting information on Active Directory domain accounts. |
| T1087.002 Domain Account |
MalwareCobalt Strike | Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group. |
| T1087.002 Domain Account |
MalwareValak | Valak has the ability to enumerate domain admin accounts. |
| T1087.002 Domain Account |
MalwareBoomBox | BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users. |
| T1087.002 Domain Account |
MalwareLAMEHUG | LAMEHUG can use dsquery to enumerate domain user information. |
| T1087.002 Domain Account |
MalwareIceApple | The IceApple Active Directory Querier module can perform authenticated requests against an Active Directory server. |
| T1087.002 Domain Account |
MalwareQilin | Qilin can use PowerShell cmdlets to enumerate domain users. |
| T1087.002 Domain Account |
MalwareSoreFang | SoreFang can enumerate domain accounts via |
| T1087.002 Domain Account |
MalwareOSInfo | OSInfo enumerates local and domain users |
| T1087.002 Domain Account |
ToolNet | Net commands used with the |
| T1087.002 Domain Account |
ToolBloodHound | BloodHound can collect information about domain users, including identification of domain admin accounts. |
| T1087.002 Domain Account |
ToolSILENTTRINITY | SILENTTRINITY can use `System.Security.AccessControl` namespaces to retrieve domain user information. |
| T1087.002 Domain Account |
ToolEmpire | Empire can acquire local and domain user account information. |
| T1087.002 Domain Account |
Tooldsquery | dsquery can be used to gather information on user accounts within a domain. |
| T1087.002 Domain Account |
ToolPoshC2 | PoshC2 can enumerate local and domain user account information. |
| T1087.002 Domain Account |
ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery. |
| T1087.002 Domain Account |
ToolCrackMapExec | CrackMapExec can enumerate the domain user accounts on a targeted system. |
| T1087.002 Domain Account |
ToolAdFind | AdFind can enumerate domain users. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.