Permission Groups Discovery

T1069

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may attempt to discover group and permission settings. This information can help adversaries determine which user accounts and groups are available, the membership of users in particular groups, and which users and groups have elevated permissions.

Adversaries may attempt to discover group permission settings in many different ways. This data may provide the adversary with information about the compromised environment that can be used in follow-on activity and targeting.

Detection rules60

Rules on DetectionCode tagged with T1069 or one of its sub-techniques.

Sigma25

RuleLevelLog sourceTechnique
BloodHound Collection Fileshighwindows / file_eventT1069.001 T1069.002
HackTool - Bloodhound/Sharphound Executionhighwindows / process_creationT1069.001 T1069.002
HackTool - SharpView Executionhighwindows / process_creationT1069.002
Malicious PowerShell Commandlets - PoshModulehighwindows / ps_moduleT1069 T1069.001 T1069.002
Malicious PowerShell Commandlets - ProcessCreationhighwindows / process_creationT1069 T1069.001 T1069.002
Malicious PowerShell Commandlets - ScriptBlockhighwindows / ps_scriptT1069 T1069.001 T1069.002
PUA - AdFind Suspicious Executionhighwindows / process_creationT1069.002
Reconnaissance Activityhighwindows / NULLT1069.002
Renamed AdFind Executionhighwindows / process_creationT1069.002
Suspicious Active Directory Database Snapshot Via ADExplorerhighwindows / process_creationT1069.002
Active Directory Database Snapshot Via ADExplorermediumwindows / process_creationT1069.002
ADExplorer Writing Complete AD Snapshot Into .dat Filemediumwindows / file_eventT1069.002
Permission Check Via Accesschk.EXEmediumwindows / process_creationT1069.001
Potential Active Directory Reconnaissance/Enumeration Via LDAPmediumwindows / NULLT1069.002
Active Directory Group Enumeration With Get-AdGrouplowwindows / ps_scriptT1069.002

Splunk35

RuleTypeRiskData sourceTechnique
ASL AWS IAM Successful Group DeletionHuntingNULLASL AWS CloudTrailT1069.003
AWS IAM Successful Group DeletionHuntingNULLAWS CloudTrail DeleteGroupT1069.003
Detect AzureHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1069.001 T1069.002
Detect AzureHound File ModificationsTTPNULLSysmon EventID 11T1069.001 T1069.002
Detect SharpHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1069.001 T1069.002
Detect SharpHound File ModificationsTTPNULLSysmon EventID 11T1069.001 T1069.002
Detect SharpHound UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1069.001 T1069.002
Domain Group Discovery with AdsisearcherTTPNULLPowershell Script Block Logging 4104T1069.002
Domain Group Discovery With DsqueryAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1069.002
Domain Group Discovery With NetHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1069.002
Domain Group Discovery With WmicHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1069.002
Elevated Group Discovery With NetTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1069.002
Elevated Group Discovery with PowerViewHuntingNULLPowershell Script Block Logging 4104T1069.002
Elevated Group Discovery With WmicTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1069.002
Get WMIObject Group DiscoveryHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1069.001

Sub-techniques3

IDNameExamples
T1069.001Local Groups32
T1069.002Domain Groups38
T1069.003Cloud Groups5

Groups6

Software6

Campaigns1

Procedure examples13

Groups6

Used byProcedure example
GroupAPT3

APT3 has a tool that can enumerate the permissions associated with Windows groups.

GroupAPT41

APT41 used net group commands to enumerate various Windows user groups and permissions.

GroupFIN13

FIN13 has enumerated all users and roles from a victim's main treasury system.

GroupScattered Spider

Scattered Spider has enumerated the vSphere Admins and ESX Admins groups in targeted environments.

GroupTA505

TA505 has used TinyMet to enumerate members of privileged groups. TA505 has also run net group /domain.

GroupVolt Typhoon

Volt Typhoon has used commercial tools, LOTL utilities, and appliances already present on the system for group and user discovery.

Software6

Used byProcedure example
MalwareCarbon

Carbon uses the net group command.

MalwareIcedID

IcedID has the ability to identify Workgroup membership.

MalwareMURKYTOP

MURKYTOP has the capability to retrieve information about groups.

ToolShimRatReporter

ShimRatReporter gathered the local privileges for the infected host.

MalwareSiloscape

Siloscape checks for Kubernetes node permissions.

MalwareTrickBot

TrickBot can identify the groups the user on a compromised host belongs to.

Campaigns1

Used byProcedure example
CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used the `Get-ManagementRoleAssignment` PowerShell cmdlet to enumerate Exchange management role assignments through an Exchange Management Shell.

References1

  1. CrowdStrike BloodHound April 2018 Open source
    Red Team Labs. (2018, April 24). Hidden Administrative Accounts: BloodHound to the Rescue. Retrieved October 28, 2020.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.