Sub-technique of T1069 Permission Groups Discovery.View on attack.mitre.org
Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.
Commands such as net localgroup of the Net utility, dscl . -list /Groups on macOS, and groups on Linux can list local groups.
Rules on DetectionCode tagged with T1069.001.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Detect AzureHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect AzureHound File Modifications | TTP | NULL | Sysmon EventID 11 |
| Detect SharpHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect SharpHound File Modifications | TTP | NULL | Sysmon EventID 11 |
| Detect SharpHound Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Get WMIObject Group Discovery | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Get WMIObject Group Discovery with Script Block Logging | Hunting | NULL | Powershell Script Block Logging 4104 |
| Net Localgroup Discovery | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Network Traffic to Active Directory Web Services Protocol | Hunting | NULL | Sysmon EventID 3 |
| PowerShell Get LocalGroup Discovery | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Powershell Get LocalGroup Discovery with Script Block Logging | Hunting | NULL | Powershell Script Block Logging 4104 |
| Windows Admin Permission Discovery | Anomaly | NULL | Sysmon EventID 11 |
| Windows Group Discovery Via Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows SOAPHound Binary Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Wmic Group Discovery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Used by | Procedure example |
|---|---|
| Groupadmin@338 | admin@338 actors used the following command following exploitation of a machine with LOWBALL malware to list local groups: |
| GroupChimera | Chimera has used |
| GroupHEXANE | HEXANE has run `net localgroup` to enumerate local groups. |
| GroupOilRig | OilRig has used |
| GroupTonto Team | Tonto Team has used the |
| GroupTurla | Turla has used |
| GroupVolt Typhoon | Volt Typhoon has run `net localgroup administrators` in compromised environments to enumerate accounts. |
| Used by | Procedure example |
|---|---|
| ToolBloodHound | BloodHound can collect information about local groups and members. |
| MalwareCaterpillar WebShell | Caterpillar WebShell can obtain a list of local groups of users from a system. |
| MalwareCobalt Strike | Cobalt Strike can use |
| MalwareEmissary | Emissary has the capability to execute the command |
| MalwareEpic | Epic gathers information on local group names. |
| MalwareExbyte | Exbyte checks whether the process is running with privileged local access during execution. |
| MalwareFlagpro | Flagpro has been used to execute the |
| MalwareFlawedAmmyy | FlawedAmmyy enumerates the privilege level of the victim during the initial infection. |
| Used by | Procedure example |
|---|---|
| CampaignC0015 | During C0015, the threat actors used the command `net localgroup "adminstrator" ` to identify accounts with local administrator rights. |
| CampaignOperation CuckooBees | During Operation CuckooBees, the threat actors used the `net group` command as part of their advanced reconnaissance. |
| CampaignOperation Digital Eye | During Operation Digital Eye, threat actors used the local.exe tool to view group memberships. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used the command `net localgroup administrators` to list all administrators part of a local group. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.