Domain Account

T1087.002

Sub-technique of T1087 Account Discovery.View on attack.mitre.org

About this technique

Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.

Commands such as net user /domain and net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain users and groups. PowerShell cmdlets including Get-ADUser and Get-ADGroupMember may enumerate members of Active Directory groups.

Detection rules50

Rules on DetectionCode tagged with T1087.002.

Sigma20

Splunk30

RuleTypeRiskData source
Account Discovery With Net AppTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
AdsiSearcher Account DiscoveryTTPNULLPowershell Script Block Logging 4104
Detect AzureHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect AzureHound File ModificationsTTPNULLSysmon EventID 11
Detect SharpHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect SharpHound File ModificationsTTPNULLSysmon EventID 11
Detect SharpHound UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Domain Account Discovery with DsqueryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Domain Account Discovery With Net AppTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Domain Account Discovery with WmicTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Get ADUser with PowerShellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Get ADUser with PowerShell Script BlockHuntingNULLPowershell Script Block Logging 4104
Get DomainUser with PowerShellTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Get DomainUser with PowerShell Script BlockTTPNULLPowershell Script Block Logging 4104
GetWmiObject DS User with PowerShellAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups29

Show 5 more

Software28

Show 4 more

Campaigns4

Procedure examples61

Groups29

Used byProcedure example
GroupAPT41

APT41 used built-in net commands to enumerate domain administrator users.

GroupBlackByte

BlackByte has used tools such as AdFind to identify and enumerate domain accounts.

GroupBRONZE BUTLER

BRONZE BUTLER has used net user /domain to identify account information.

GroupChimera

Chimera has has used net user /dom and net user Administrator to enumerate domain accounts including administrator accounts.

GroupDragonfly

Dragonfly has used batch scripts to enumerate users on a victim domain controller.

GroupFIN13

FIN13 can identify user accounts associated with a Service Principal Name and query Service Principal Names within the domain by utilizing the following scripts: `GetUserSPNs.vbs` and `querySpn.vbs`.

GroupFIN6

FIN6 has used Metasploit’s PsExec NTDSGRAB module to obtain a copy of the victim's Active Directory database.

GroupFIN7

FIN7 has used the PowerShell script 3CF9.ps1 and the executable WsTaskLoad to enumerate domain administrations by executing `net group “Domain Admins” /domain`. FIN7 has also used csvde.exe, which is a built-in Windows command line tool, to export Active Directory information.

View all 29 groups examples

Software28

Used byProcedure example
ToolAdFind

AdFind can enumerate domain users.

MalwareBankshot

Bankshot gathers domain and account names/information through process monitoring.

MalwareBazar

Bazar has the ability to identify domain administrator accounts.

MalwareBlackCat

BlackCat can utilize `net use` commands to identify domain users.

ToolBloodHound

BloodHound can collect information about domain users, including identification of domain admin accounts.

MalwareBoomBox

BoomBox has the ability to execute an LDAP query to enumerate the distinguished name, SAM account name, and display name for all domain users.

ToolBrute Ratel C4

Brute Ratel C4 can use LDAP queries, `net group "Domain Admins" /domain` and `net user /domain` for discovery.

MalwareCobalt Strike

Cobalt Strike can determine if the user on an infected machine is in the admin or domain admin group.

View all 28 software examples

Campaigns4

Used byProcedure example
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `dsquery` and `dsget` commands to get domain environment information and to query users in administrative groups.

CampaignOperation Dream Job

During Operation Dream Job, Lazarus Group queried compromised victim's active directory servers to obtain the list of employees including administrator accounts.

CampaignOperation Wocao

During Operation Wocao, threat actors used the `net` command to retrieve information about domain accounts.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used PowerShell to discover domain accounts by exectuing `Get-ADUser` and `Get-ADGroupMember`.

References1

  1. CrowdStrike StellarParticle January 2022 Open source
    CrowdStrike. (2022, January 27). Early Bird Catches the Wormhole: Observations from the StellarParticle Campaign. Retrieved February 7, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.