Real-world descriptions of how a group, tool or campaign used a technique.
40 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1033 System Owner/User Discovery |
GroupAPT38 | APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users. |
| T1033 System Owner/User Discovery |
GroupGALLIUM | GALLIUM used |
| T1033 System Owner/User Discovery |
GroupAPT3 | An APT3 downloader uses the Windows command |
| T1033 System Owner/User Discovery |
GroupKimsuky | Kimsuky has gathered the identity of the user by querying `System.Security.Principal` namespace using the `GetCurrent()` method. |
| T1033 System Owner/User Discovery |
GroupVolt Typhoon | Volt Typhoon has used public tools and executed the PowerShell command `Get-EventLog security -instanceid 4624` to identify associated user and computer account names. |
| T1033 System Owner/User Discovery |
GroupPatchwork | Patchwork collected the victim username and whether it was running as admin, then sent the information to its C2 server. |
| T1033 System Owner/User Discovery |
GroupAPT41 | APT41 has executed |
| T1033 System Owner/User Discovery |
GroupDragonfly | Dragonfly used the command |
| T1033 System Owner/User Discovery |
GroupAPT32 | APT32 collected the victim's username and executed the |
| T1033 System Owner/User Discovery |
GroupHAFNIUM | HAFNIUM has used `whoami` to gather user information. |
| T1033 System Owner/User Discovery |
GroupMuddyWater | MuddyWater has used malware that can collect the victim’s username. |
| T1033 System Owner/User Discovery |
GroupGamaredon Group | A Gamaredon Group file stealer can gather the victim's username to send to a C2 server. |
| T1033 System Owner/User Discovery |
GroupStorm-1811 | Storm-1811 has used `whoami.exe` to determine if the active user on a compromised system is an administrator. |
| T1033 System Owner/User Discovery |
GroupFIN7 | FIN7 has used the command `cmd.exe /C quser` to collect user session information. |
| T1033 System Owner/User Discovery |
GroupSandworm Team | Sandworm Team has collected the username from a compromised host. |
| T1033 System Owner/User Discovery |
GroupSidewinder | Sidewinder has used tools to identify the user of a compromised host. |
| T1033 System Owner/User Discovery |
GroupZIRCONIUM | ZIRCONIUM has used a tool to capture the username on a compromised host in order to register it with C2. |
| T1033 System Owner/User Discovery |
GroupAPT39 | |
| T1033 System Owner/User Discovery |
GroupAPT37 | APT37 identifies the victim username. |
| T1033 System Owner/User Discovery |
GroupOilRig | OilRig has run |
| T1033 System Owner/User Discovery |
GroupTropic Trooper | Tropic Trooper used |
| T1033 System Owner/User Discovery |
GroupAquatic Panda | Aquatic Panda gathers information on recently logged-in users on victim devices. |
| T1033 System Owner/User Discovery |
GroupKe3chang | Ke3chang has used implants capable of collecting the signed-in username. |
| T1033 System Owner/User Discovery |
GroupWinter Vivern | Winter Vivern PowerShell scripts execute `whoami` to identify the executing user. |
| T1033 System Owner/User Discovery |
GroupStealth Falcon | Stealth Falcon malware gathers the registered user and primary owner name via WMI. |
| T1033 System Owner/User Discovery |
GroupChimera | Chimera has used the |
| T1033 System Owner/User Discovery |
GroupMirrorFace | MirrorFace has used Windows native tools to enumerate user information. |
| T1033 System Owner/User Discovery |
GroupMedusa Group | Medusa Group has utilized PsExec to execute `quser` to discover the user session information. |
| T1033 System Owner/User Discovery |
GroupWindshift | Windshift has used malware to identify the username on a compromised host. |
| T1033 System Owner/User Discovery |
GroupLuminousMoth | LuminousMoth has used a malicious DLL to collect the username from compromised hosts. |
| T1033 System Owner/User Discovery |
GroupLazarus Group | Various Lazarus Group malware enumerates logged-on users. |
| T1033 System Owner/User Discovery |
GroupEarth Lusca | Earth Lusca collected information on user accounts via the |
| T1033 System Owner/User Discovery |
GroupWizard Spider | Wizard Spider has used "whoami" to identify the local user and their privileges. |
| T1033 System Owner/User Discovery |
GroupMoonstone Sleet | Moonstone Sleet deployed various malware such as YouieLoader that can perform system user discovery actions. |
| T1033 System Owner/User Discovery |
GroupHEXANE | HEXANE has run `whoami` on compromised machines to identify the current user. |
| T1033 System Owner/User Discovery |
GroupMagic Hound | Magic Hound malware has obtained the victim username and sent it to the C2 server. |
| T1033 System Owner/User Discovery |
GroupThreat Group-3390 | Threat Group-3390 has used `whoami` to collect system user information. |
| T1033 System Owner/User Discovery |
GroupFIN10 | FIN10 has used Meterpreter to enumerate users on remote systems. |
| T1033 System Owner/User Discovery |
GroupFIN8 | FIN8 has executed the command `quser` to display the session details of a compromised machine. |
| T1033 System Owner/User Discovery |
GroupAPT19 | APT19 used an HTTP malware variant and a Port 22 malware variant to collect the victim’s username. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.