Sub-technique of T1087 Account Discovery.View on attack.mitre.org
Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.
Commands such as net user and net localgroup of the Net utility and id and groups on macOS and Linux can list local users and groups. On Linux, local users can also be enumerated through the use of the /etc/passwd file. On macOS, the dscl . list /Users command can be used to enumerate local accounts. On ESXi servers, the `esxcli system account list` command can list local user accounts.
Rules on DetectionCode tagged with T1087.001.
| Rule | Level | Log source |
|---|---|---|
| BloodHound Collection Files | high | windows / file_event |
| HackTool - Bloodhound/Sharphound Execution | high | windows / process_creation |
| Malicious PowerShell Commandlets - PoshModule | high | windows / ps_module |
| Malicious PowerShell Commandlets - ProcessCreation | high | windows / process_creation |
| Malicious PowerShell Commandlets - ScriptBlock | high | windows / ps_script |
| Suspicious Group And Account Reconnaissance Activity Using Net.EXE | medium | windows / process_creation |
| Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet | medium | windows / process_creation |
| Suspicious Use of PsLogList | medium | windows / process_creation |
| Cisco Collect Data | low | cisco / NULL |
| Local Accounts Discovery | low | windows / process_creation |
| Local System Accounts Discovery - Linux | low | linux / process_creation |
| Local System Accounts Discovery - MacOs | low | macos / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect AzureHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect AzureHound File Modifications | TTP | NULL | Sysmon EventID 11 |
| Detect SharpHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect SharpHound File Modifications | TTP | NULL | Sysmon EventID 11 |
| Detect SharpHound Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetLocalUser with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetLocalUser with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 |
| GetWmiObject User Account with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetWmiObject User Account with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 |
| Local Account Discovery with Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Local Account Discovery With Wmic | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Network Traffic to Active Directory Web Services Protocol | Hunting | NULL | Sysmon EventID 3 |
| Windows Account Discovery for None Disable User Account | Hunting | NULL | Powershell Script Block Logging 4104 |
| Windows SOAPHound Binary Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows User Discovery Via Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| Groupadmin@338 | admin@338 actors used the following commands following exploitation of a machine with LOWBALL malware to enumerate user accounts: |
| GroupAPT1 | APT1 used the commands |
| GroupAPT3 | APT3 has used a tool that can obtain info about local and global group users, power users, and administrators. |
| GroupAPT32 | APT32 enumerated administrative users using the commands |
| GroupAPT41 | APT41 used built-in |
| GroupAPT42 | APT42 has used the PowerShell-based POWERPOST script to collect local account names from the victim machine. |
| GroupChimera | Chimera has used |
| GroupFox Kitten | Fox Kitten has accessed ntuser.dat and UserClass.dat on compromised hosts. |
| Used by | Procedure example |
|---|---|
| MalwareAgent Tesla | Agent Tesla can collect account information from the victim’s machine. |
| MalwareBankshot | Bankshot gathers domain and account names/information through process monitoring. |
| MalwareBazar | Bazar can identify administrator accounts on an infected host. |
| MalwareBitPaymer | BitPaymer can enumerate the sessions for each user logged onto the infected host. |
| ToolBloodHound | BloodHound can identify users with local administrator rights. |
| MalwareComnie | Comnie uses the |
| MalwareDuqu | The discovery modules used with Duqu can collect information on accounts and permissions. |
| MalwareDUSTTRAP | DUSTTRAP can enumerate local user accounts. |
| Used by | Procedure example |
|---|---|
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net user` command to gather account information. |
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local.exe tool to view local account information. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.