Group Membership Reconnaissance Via Whoami.EXE

 Original Source: [Sigma source]
Title: Group Membership Reconnaissance Via Whoami.EXE
Status: test
Description:Detects the execution of whoami.exe with the /group command line flag to show group membership for the current user, account type, security identifiers (SID), and attributes.
References:
  -https://learn.microsoft.com/en-us/windows-server/administration/windows-commands/whoami
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2023-02-28
modified:None
Tags:
  • -'attack.discovery'
  • -'attack.t1033'
Logsource:
  • category: process_creation
  • product: windows
Detection:
  selection_img:
Image|endswith:'\whoami.exe' OriginalFileName:'whoami.exe'   selection_cli:
    CommandLine|contains:
      -' /groups'
      -' -groups'

  condition:all of selection_*
Falsepositives:
  -Unknown
Level: medium