Local Accounts Discovery

 Original Source: [Sigma source]
Title: Local Accounts Discovery
Status: test
Description:Local accounts, System Owner/User discovery using operating systems utilities
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1033/T1033.md
Author: Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community
Date: 2019-10-21
modified:2025-10-20
Tags:
  • -'attack.discovery'
  • -'attack.t1033'
  • -'attack.t1087.001'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_other_img:
    - Image|endswith:
      - '\whoami.exe'
      - '\quser.exe'
      - '\qwinsta.exe'
    - OriginalFileName:
      - 'whoami.exe'
      - 'quser.exe'
      - 'qwinsta.exe'
  selection_other_wmi:
    Image|endswith: '\wmic.exe'
    CommandLine|contains|all:
      -'useraccount'
      -'get'

  selection_other_cmdkey:
    Image|endswith: '\cmdkey.exe'
    CommandLine|contains: ' /l'
  selection_cmd:
    Image|endswith: '\cmd.exe'
    CommandLine|contains|all:
      -' /c'
      -'dir '
      -'\Users\'

  filter_cmd:
    CommandLine|contains: ' rmdir '
  selection_net:
    Image|endswith:
      -'\net.exe'
      -'\net1.exe'

    CommandLine|contains: 'user'
  filter_net:
    CommandLine|contains:
      -'/domain'
      -'/add'
      -'/delete'
      -'/active'
      -'/expires'
      -'/passwordreq'
      -'/scriptpath'
      -'/times'
      -'/workstations'

  condition:(selection_cmd and not filter_cmd) or (selection_net and not filter_net) or 1 of selection_other_*
Falsepositives:
  -Legitimate administrator or user enumerates local users for legitimate reason
Level: low