Technique.View on attack.mitre.org
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Various utilities and commands may acquire this information, including whoami. In macOS and Linux, the currently logged in user can be identified with w and who. On macOS the dscl . list /Users | grep -v '_' command can also be used to enumerate user accounts. Environment variables, such as %USERNAME% and $USER, may also be used to access this information.
On network devices, Network Device CLI commands such as `show users` and `show ssh` can be used to display users currently logged into the device.
Rules on DetectionCode tagged with T1033.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Check Elevated CMD using whoami | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetCurrent User with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetCurrent User with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 |
| Linux Auditd Whoami User Discovery | Anomaly | NULL | Linux Auditd Syscall |
| Linux Root Execution of id | Anomaly | NULL | Sysmon for Linux EventID 1 |
| System User Discovery With Query | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| System User Discovery With Whoami | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| User Discovery With Env Vars PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| User Discovery With Env Vars PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 |
| Windows Common Abused Cmd Shell Risk Behavior | Correlation | NULL | |
| Windows System Discovery Using ldap Nslookup | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows System Discovery Using Qwinsta | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows System Remote Discovery With Query | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows System User Discovery Via Quser | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows System User Privilege Discovery | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows WinPEAS PowerShell Script Execution | TTP | NULL | Powershell Script Block Logging 4104 |
| Used by | Procedure example |
|---|---|
| GroupAPT19 | APT19 used an HTTP malware variant and a Port 22 malware variant to collect the victim’s username. |
| GroupAPT3 | An APT3 downloader uses the Windows command |
| GroupAPT32 | APT32 collected the victim's username and executed the |
| GroupAPT37 | APT37 identifies the victim username. |
| GroupAPT38 | APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users. |
| GroupAPT39 | |
| GroupAPT41 | APT41 has executed |
| GroupAquatic Panda | Aquatic Panda gathers information on recently logged-in users on victim devices. |
| Used by | Procedure example |
|---|---|
| MalwareAction RAT | Action RAT has the ability to collect the username from an infected host. |
| MalwareAgent Tesla | Agent Tesla can collect the username from the victim’s machine. |
| MalwareAgent.btz | Agent.btz obtains the victim username and saves it to a file. |
| MalwareAmadey | Amadey has collected the user name from a compromised host using `GetUserNameA`. |
| MalwareAria-body | Aria-body has the ability to identify the username on a compromised host. |
| ToolAsyncRAT | AsyncRAT can check if the current user of a compromised system is an administrator. |
| MalwareAuTo Stealer | AuTo Stealer has the ability to collect the username from an infected host. |
| MalwareAzorult | Azorult can collect the username from the victim’s machine. |
View all 196 software examples
| Used by | Procedure example |
|---|---|
| CampaignC0017 | During C0017, APT41 used `whoami` to gather information from victim machines. |
| CampaignC0018 | During C0018, the threat actors collected `whoami` information via PowerShell scripts. |
| CampaignFrankenstein | During Frankenstein, the threat actors used Empire to enumerate hosts and gather username, machine name, and administrative permissions information. |
| CampaignNight Dragon | During Night Dragon, threat actors used password cracking and pass-the-hash tools to discover usernames and passwords. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `query user` and `whoami` commands as part of their advanced reconnaissance. |
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used `GetUserInfo` to identify current user information. |
| CampaignOperation Wocao | During Operation Wocao, threat actors enumerated sessions and users on a remote host, and identified privileged users logged into a targeted system. |
| CampaignSharePoint ToolShell Exploitation | During SharePoint ToolShell Exploitation, threat actors executed `whoami` on victim machines to enumerate user context and validate privilege levels. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.