Sub-technique of T1087 Account Discovery.View on attack.mitre.org
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.
Commands such as net user /domain and net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain users and groups. PowerShell cmdlets including Get-ADUser and Get-ADGroupMember may enumerate members of Active Directory groups.
Rules on DetectionCode tagged with T1087.002.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Account Discovery With Net App | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| AdsiSearcher Account Discovery | TTP | NULL | Powershell Script Block Logging 4104 |
| Detect AzureHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect AzureHound File Modifications | TTP | NULL | Sysmon EventID 11 |
| Detect SharpHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect SharpHound File Modifications | TTP | NULL | Sysmon EventID 11 |
| Detect SharpHound Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Domain Account Discovery with Dsquery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Domain Account Discovery With Net App | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Domain Account Discovery with Wmic | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Get ADUser with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Get ADUser with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 |
| Get DomainUser with PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Get DomainUser with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| GetWmiObject DS User with PowerShell | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| GetWmiObject DS User with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 |
| Network Traffic to Active Directory Web Services Protocol | Hunting | NULL | Sysmon EventID 3 |
| SchCache Change By App Connect And Create ADSI Object | Anomaly | NULL | Sysmon EventID 11 |
| Windows AD Abnormal Object Access Activity | Anomaly | NULL | Windows Event Log Security 4662 |
| Windows AD Privileged Object Access Activity | TTP | NULL | Windows Event Log Security 4662 |
| Windows Domain Account Discovery Via Get-NetComputer | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows Find Domain Organizational Units with GetDomainOU | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Find Interesting ACL with FindInterestingDomainAcl | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Forest Discovery with GetForestDomain | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Get Local Admin with FindLocalAdminAccess | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Linked Policies In ADSI Discovery | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows Root Domain linked policies Discovery | Anomaly | NULL | Powershell Script Block Logging 4104 |
| Windows SOAPHound Binary Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Suspect Process With Authentication Traffic | Anomaly | NULL | Sysmon EventID 3 |
| Windows User Discovery Via Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| GroupAPT41 | APT41 used built-in |
| GroupBlackByte | BlackByte has used tools such as AdFind to identify and enumerate domain accounts. |
| GroupBRONZE BUTLER | BRONZE BUTLER has used |
| GroupChimera | Chimera has has used |
| GroupDragonfly | Dragonfly has used batch scripts to enumerate users on a victim domain controller. |
| GroupFIN13 | FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`. |
| GroupFIN6 | FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database. |
| GroupFIN7 | FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information. |
| Used by | Procedure example |
|---|---|
| ToolAdFind | AdFind can enumerate domain users. |
| MalwareBankshot | Bankshot gathers domain and account names/information through process monitoring. |
| MalwareBazar | Bazar has the ability to identify domain administrator accounts. |
| MalwareBlackCat | BlackCat can utilize `net use` commands to identify domain users. |
| ToolBloodHound | BloodHound can collect information about domain users, including identification of domain admin accounts. |
| MalwareBoomBox | BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users. |
| ToolBrute Ratel C4 | Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery. |
| MalwareCobalt Strike | Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group. |
| Used by | Procedure example |
|---|---|
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `dsquery` and `dsget` commands to get domain environment information and to query users in administrative groups. |
| CampaignOperation Dream Job | During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used the `net` command to retrieve information about domain accounts. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.