System Owner/User Discovery

T1033

Technique.View on attack.mitre.org

About this technique

Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Various utilities and commands may acquire this information, including whoami. In macOS and Linux, the currently logged in user can be identified with w and who. On macOS the dscl . list /Users | grep -v '_' command can also be used to enumerate user accounts. Environment variables, such as %USERNAME% and $USER, may also be used to access this information.

On network devices, Network Device CLI commands such as `show users` and `show ssh` can be used to display users currently logged into the device.

Detection rules46

Rules on DetectionCode tagged with T1033.

Sigma30

RuleLevelLog source
Renamed Whoami Executioncriticalwindows / process_creation
Chopper Webshell Process Patternhighwindows / process_creation
HackTool - SharpLdapWhoami Executionhighwindows / process_creation
HackTool - SharpView Executionhighwindows / process_creation
Possible DCSync Attackhighrpc_firewall / application
Security Privileges Enumeration Via Whoami.EXEhighwindows / process_creation
SharpHound Recon Sessionshighrpc_firewall / application
Webshell Detection With Command Line Keywordshighwindows / process_creation
Webshell Hacking Activity Patternshighwindows / process_creation
WhoAmI as Parameterhighwindows / process_creation
Whoami.EXE Execution From Privileged Processhighwindows / process_creation
Computer Discovery And Export Via Get-ADComputer Cmdletmediumwindows / process_creation
Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShellmediumwindows / ps_script
Enumerate All Information With Whoami.EXEmediumwindows / process_creation
ESXi Network Configuration Discovery Via ESXCLImediumlinux / process_creation

Splunk16

RuleTypeRiskData source
Check Elevated CMD using whoamiTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetCurrent User with PowerShellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetCurrent User with PowerShell Script BlockHuntingNULLPowershell Script Block Logging 4104
Linux Auditd Whoami User DiscoveryAnomalyNULLLinux Auditd Syscall
Linux Root Execution of idAnomalyNULLSysmon for Linux EventID 1
System User Discovery With QueryHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
System User Discovery With WhoamiHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
User Discovery With Env Vars PowerShellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
User Discovery With Env Vars PowerShell Script BlockHuntingNULLPowershell Script Block Logging 4104
Windows Common Abused Cmd Shell Risk BehaviorCorrelationNULL
Windows System Discovery Using ldap NslookupAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows System Discovery Using QwinstaHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows System Remote Discovery With QueryHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows System User Discovery Via QuserHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows System User Privilege DiscoveryHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups40

Show 16 more

Software196

Show 172 more

Campaigns8

Procedure examples244

Groups40

Used byProcedure example
GroupAPT19

APT19 used an HTTP malware variant and a Port 22 malware variant to collect the victim’s username.

GroupAPT3

An APT3 downloader uses the Windows command "cmd.exe" /C whoami to verify that it is running with the elevated privileges of “System.”

GroupAPT32

APT32 collected the victim's username and executed the whoami command on the victim's machine. APT32 executed shellcode to collect the username on the victim's machine.

GroupAPT37

APT37 identifies the victim username.

GroupAPT38

APT38 has identified primary users, currently logged in users, sets of users that commonly use a system, or inactive users.

GroupAPT39

APT39 used Remexi to collect usernames from the system.

GroupAPT41

APT41 has executed whoami commands, including using the WMIEXEC utility to execute this on remote machines.

GroupAquatic Panda

Aquatic Panda gathers information on recently logged-in users on victim devices.

View all 40 groups examples

Software196

Used byProcedure example
MalwareAction RAT

Action RAT has the ability to collect the username from an infected host.

MalwareAgent Tesla

Agent Tesla can collect the username from the victim’s machine.

MalwareAgent.btz

Agent.btz obtains the victim username and saves it to a file.

MalwareAmadey

Amadey has collected the user name from a compromised host using `GetUserNameA`.

MalwareAria-body

Aria-body has the ability to identify the username on a compromised host.

ToolAsyncRAT

AsyncRAT can check if the current user of a compromised system is an administrator.

MalwareAuTo Stealer

AuTo Stealer has the ability to collect the username from an infected host.

MalwareAzorult

Azorult can collect the username from the victim’s machine.

View all 196 software examples

Campaigns8

Used byProcedure example
CampaignC0017

During C0017, APT41 used `whoami` to gather information from victim machines.

CampaignC0018

During C0018, the threat actors collected `whoami` information via PowerShell scripts.

CampaignFrankenstein

During Frankenstein, the threat actors used Empire to enumerate hosts and gather username, machine name, and administrative permissions information.

CampaignNight Dragon

During Night Dragon, threat actors used password cracking and pass-the-hash tools to discover usernames and passwords.

CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `query user` and `whoami` commands as part of their advanced reconnaissance.

CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used `GetUserInfo` to identify current user information.

CampaignOperation Wocao

During Operation Wocao, threat actors enumerated sessions and users on a remote host, and identified privileged users logged into a targeted system.

CampaignSharePoint ToolShell Exploitation

During SharePoint ToolShell Exploitation, threat actors executed `whoami` on victim machines to enumerate user context and validate privilege levels.

References2

  1. US-CERT TA18-106A Network Infrastructure Devices 2018 Open source
    US-CERT. (2018, April 20). Russian State-Sponsored Cyber Actors Targeting Network Infrastructure Devices. Retrieved October 19, 2020.
  2. show_ssh_users_cmd_cisco Open source
    Cisco. (2023, March 7). Cisco IOS Security Command Reference: Commands S to Z . Retrieved July 13, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.