Technique with 3 sub-techniques.View on attack.mitre.org
Adversaries may attempt to discover group and permission settings. This information can help adversaries determine which user accounts and groups are available, the membership of users in particular groups, and which users and groups have elevated permissions.
Adversaries may attempt to discover group permission settings in many different ways. This data may provide the adversary with information about the compromised environment that can be used in follow-on activity and targeting.
Rules on DetectionCode tagged with T1069 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| ASL AWS IAM Successful Group Deletion | Hunting | NULL | ASL AWS CloudTrail | T1069.003 |
| AWS IAM Successful Group Deletion | Hunting | NULL | AWS CloudTrail DeleteGroup | T1069.003 |
| Detect AzureHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.001 T1069.002 |
| Detect AzureHound File Modifications | TTP | NULL | Sysmon EventID 11 | T1069.001 T1069.002 |
| Detect SharpHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.001 T1069.002 |
| Detect SharpHound File Modifications | TTP | NULL | Sysmon EventID 11 | T1069.001 T1069.002 |
| Detect SharpHound Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.001 T1069.002 |
| Domain Group Discovery with Adsisearcher | TTP | NULL | Powershell Script Block Logging 4104 | T1069.002 |
| Domain Group Discovery With Dsquery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.002 |
| Domain Group Discovery With Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.002 |
| Domain Group Discovery With Wmic | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.002 |
| Elevated Group Discovery With Net | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.002 |
| Elevated Group Discovery with PowerView | Hunting | NULL | Powershell Script Block Logging 4104 | T1069.002 |
| Elevated Group Discovery With Wmic | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.002 |
| Get WMIObject Group Discovery | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.001 |
| Get WMIObject Group Discovery with Script Block Logging | Hunting | NULL | Powershell Script Block Logging 4104 | T1069.001 |
| GetAdGroup with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.002 |
| GetAdGroup with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 | T1069.002 |
| GetDomainGroup with PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.002 |
| GetDomainGroup with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 | T1069.002 |
| GetWmiObject Ds Group with PowerShell | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.002 |
| GetWmiObject Ds Group with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 | T1069.002 |
| Net Localgroup Discovery | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.001 |
| Network Traffic to Active Directory Web Services Protocol | Hunting | NULL | Sysmon EventID 3 | T1069.001 T1069.002 |
| PowerShell Get LocalGroup Discovery | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.001 |
| Powershell Get LocalGroup Discovery with Script Block Logging | Hunting | NULL | Powershell Script Block Logging 4104 | T1069.001 |
| Windows Admin Permission Discovery | Anomaly | NULL | Sysmon EventID 11 | T1069.001 |
| Windows Azure PowerShell Module Installation Via PowerShell Script | Anomaly | NULL | Powershell Script Block Logging 4104 | T1069.003 |
| Windows Group Discovery Via Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.001 T1069.002 |
| Windows Ldifde Directory Object Behavior | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.002 |
| Windows Post Exploitation Risk Behavior | Correlation | NULL | T1069 | |
| Windows PowerView AD Access Control List Enumeration | TTP | NULL | Powershell Script Block Logging 4104 | T1069 |
| Windows Sensitive Group Discovery With Net | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.002 |
| Windows SOAPHound Binary Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.001 T1069.002 |
| Wmic Group Discovery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1069.001 |
| Used by | Procedure example |
|---|---|
| GroupAPT3 | APT3 has a tool that can enumerate the permissions associated with Windows groups. |
| GroupAPT41 | APT41 used |
| GroupFIN13 | FIN13 has enumerated all users and roles from a victim's main treasury system. |
| GroupScattered Spider | Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments. |
| GroupTA505 | TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run |
| GroupVolt Typhoon | Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery. |
| Used by | Procedure example |
|---|---|
| MalwareCarbon | Carbon uses the |
| MalwareIcedID | IcedID has the ability to identify Workgroup membership. |
| MalwareMURKYTOP | MURKYTOP has the capability to retrieve information about groups. |
| ToolShimRatReporter | ShimRatReporter gathered the local privileges for the infected host. |
| MalwareSiloscape | Siloscape checks for Kubernetes node permissions. |
| MalwareTrickBot | TrickBot can identify the groups the user on a compromised host belongs to. |
| Used by | Procedure example |
|---|---|
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used the `Get-ManagementRoleAssignment` PowerShell cmdlet to enumerate Exchange management role assignments through an Exchange Management Shell. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.