Local Groups

T1069.001

Sub-technique of T1069 Permission Groups Discovery.View on attack.mitre.org

About this technique

Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.

Commands such as net localgroup of the Net utility, dscl . -list /Groups on macOS, and groups on Linux can list local groups.

Detection rules30

Rules on DetectionCode tagged with T1069.001.

Sigma15

Splunk15

RuleTypeRiskData source
Detect AzureHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect AzureHound File ModificationsTTPNULLSysmon EventID 11
Detect SharpHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect SharpHound File ModificationsTTPNULLSysmon EventID 11
Detect SharpHound UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Get WMIObject Group DiscoveryHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Get WMIObject Group Discovery with Script Block LoggingHuntingNULLPowershell Script Block Logging 4104
Net Localgroup DiscoveryHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Network Traffic to Active Directory Web Services ProtocolHuntingNULLSysmon EventID 3
PowerShell Get LocalGroup DiscoveryHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Powershell Get LocalGroup Discovery with Script Block LoggingHuntingNULLPowershell Script Block Logging 4104
Windows Admin Permission DiscoveryAnomalyNULLSysmon EventID 11
Windows Group Discovery Via NetHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows SOAPHound Binary ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Wmic Group DiscoveryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups7

Software21

Campaigns4

Procedure examples32

Groups7

Used byProcedure example
Groupadmin@338

admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to list local groups: net localgroup administrator >> %temp%\download

GroupChimera

Chimera has used net localgroup administrators to identify accounts with local administrative rights.

GroupHEXANE

HEXANE has run `net localgroup` to enumerate local groups.

GroupOilRig

OilRig has used net localgroup administrators to find local administrators on compromised systems.

GroupTonto Team

Tonto Team has used the ShowLocalGroupDetails command to identify administrator, user, and guest accounts on a compromised host.

GroupTurla

Turla has used net localgroup and net localgroup Administrators to enumerate group information, including members of the local administrators group.

GroupVolt Typhoon

Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts.

Software21

Used byProcedure example
ToolBloodHound

BloodHound can collect information about local groups and members.

MalwareCaterpillar WebShell

Caterpillar WebShell can obtain a list of local groups of users from a system.

MalwareCobalt Strike

Cobalt Strike can use net localgroup to list local groups on a system.

MalwareEmissary

Emissary has the capability to execute the command net localgroup administrators.

MalwareEpic

Epic gathers information on local group names.

MalwareExbyte

Exbyte checks whether the process is running with privileged local access during execution.

MalwareFlagpro

Flagpro has been used to execute the net localgroup administrators command on a targeted system.

MalwareFlawedAmmyy

FlawedAmmyy enumerates the privilege level of the victim during the initial infection.

View all 21 software examples

Campaigns4

Used byProcedure example
CampaignC0015

During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net group` command as part of their advanced reconnaissance.

CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local.exe tool to view group memberships.

CampaignOperation Wocao

During Operation Wocao, threat actors used the command `net localgroup administrators` to list all administrators part of a local group.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.