Account Discovery

T1087

Technique with 4 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts exist, which can aid in follow-on behavior such as brute-forcing, spear-phishing attacks, or account takeovers (e.g., Valid Accounts).

Adversaries may use several methods to enumerate accounts, including abuse of existing tools, built-in commands, and potential misconfigurations that leak account names and roles or permissions in the targeted environment.

For examples, cloud environments typically provide easily accessible interfaces to obtain user lists. On hosts, adversaries can use default PowerShell and other command line functionality to identify accounts. Information about email addresses and accounts may also be extracted by searching an infected system’s files.

Detection rules84

Rules on DetectionCode tagged with T1087 or one of its sub-techniques.

Sigma39

RuleLevelLog sourceTechnique
AD Privileged Users or Groups Reconnaissancehighwindows / NULLT1087.002
BloodHound Collection Fileshighwindows / file_eventT1087.001 T1087.002
Chopper Webshell Process Patternhighwindows / process_creationT1087
Discovery Using AzureHoundhighazure / NULLT1087.004
HackTool - Bloodhound/Sharphound Executionhighwindows / process_creationT1087.001 T1087.002
HackTool - SOAPHound Executionhighwindows / process_creationT1087
HackTool - winPEAS Executionhighwindows / process_creationT1087
Hacktool Rulerhighwindows / NULLT1087
Malicious PowerShell Commandlets - PoshModulehighwindows / ps_moduleT1087 T1087.001 T1087.002
Malicious PowerShell Commandlets - ProcessCreationhighwindows / process_creationT1087 T1087.001 T1087.002
Malicious PowerShell Commandlets - ScriptBlockhighwindows / ps_scriptT1087 T1087.001 T1087.002
Network Reconnaissance Activityhighwindows / process_creationT1087
PUA - AdFind Suspicious Executionhighwindows / process_creationT1087.002
PUA - Seatbelt Executionhighwindows / process_creationT1087
PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXEhighwindows / process_creationT1087.002

Splunk45

RuleTypeRiskData sourceTechnique
Account Discovery With Net AppTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1087.002
AdsiSearcher Account DiscoveryTTPNULLPowershell Script Block Logging 4104T1087.002
Azure AD AzureHound UserAgent DetectedTTPNULLAzure Active Directory NonInteractiveUserSignInLogs, Azure Active Directory MicrosoftGraphActivityLogsT1087.004
Azure AD Service Principal EnumerationTTPNULLAzure Active Directory MicrosoftGraphActivityLogsT1087.004
Detect AzureHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1087.001 T1087.002
Detect AzureHound File ModificationsTTPNULLSysmon EventID 11T1087.001 T1087.002
Detect SharpHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1087.001 T1087.002
Detect SharpHound File ModificationsTTPNULLSysmon EventID 11T1087.001 T1087.002
Detect SharpHound UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1087.001 T1087.002
Domain Account Discovery with DsqueryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1087.002
Domain Account Discovery With Net AppTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1087.002
Domain Account Discovery with WmicTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1087.002
Enumerate Users Local Group Using TelegramTTPNULLWindows Event Log Security 4798T1087
Get ADUser with PowerShellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1087.002
Get ADUser with PowerShell Script BlockHuntingNULLPowershell Script Block Logging 4104T1087.002

Sub-techniques4

IDNameExamples
T1087.001Local Account65
T1087.002Domain Account61
T1087.003Email Account15
T1087.004Cloud Account7

Groups3

Software5

Campaigns2

Procedure examples10

Groups3

Used byProcedure example
GroupAquatic Panda

Aquatic Panda used the last command in Linux environments to identify recently logged-in users on victim machines.

GroupFIN13

FIN13 has enumerated all users and their roles from a victim's main treasury system.

GroupScattered Spider

Scattered Spider has identified vSphere administrator accounts.

Software5

Used byProcedure example
MalwareHavoc

Havoc can identify privileged user accounts on infected systems.

ToolShimRatReporter

ShimRatReporter listed all non-privileged and privileged accounts available on the machine.

MalwareTONESHELL

TONESHELL included functionality to retrieve a list of user accounts.

MalwareWoody RAT

Woody RAT can identify administrator accounts on an infected machine.

MalwareXCSSET

XCSSET attempts to discover accounts from various locations such as a user's Evernote, AppleID, Telegram, Skype, and WeChat data.

Campaigns2

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal database user account tables to enumerate accounts and identify high-privilege accounts within compromised environments.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 obtained a list of users and their roles from an Exchange server using `Get-ManagementRoleAssignment`.

References2

  1. AWS List Users Open source
    Amazon. (n.d.). List Users. Retrieved August 11, 2020.
  2. Google Cloud - IAM Servie Accounts List API Open source
    Google. (2020, June 23). gcloud iam service-accounts list. Retrieved August 4, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.