Local Account

T1087.001

Sub-technique of T1087 Account Discovery.View on attack.mitre.org

About this technique

Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.

Commands such as net user and net localgroup of the Net utility and id and groups on macOS and Linux can list local users and groups. On Linux, local users can also be enumerated through the use of the /etc/passwd file. On macOS, the dscl . list /Users command can be used to enumerate local accounts. On ESXi servers, the `esxcli system account list` command can list local user accounts.

Detection rules27

Rules on DetectionCode tagged with T1087.001.

Sigma12

RuleLevelLog source
BloodHound Collection Fileshighwindows / file_event
HackTool - Bloodhound/Sharphound Executionhighwindows / process_creation
Malicious PowerShell Commandlets - PoshModulehighwindows / ps_module
Malicious PowerShell Commandlets - ProcessCreationhighwindows / process_creation
Malicious PowerShell Commandlets - ScriptBlockhighwindows / ps_script
Suspicious Group And Account Reconnaissance Activity Using Net.EXEmediumwindows / process_creation
Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdletmediumwindows / process_creation
Suspicious Use of PsLogListmediumwindows / process_creation
Cisco Collect Datalowcisco / NULL
Local Accounts Discoverylowwindows / process_creation
Local System Accounts Discovery - Linuxlowlinux / process_creation
Local System Accounts Discovery - MacOslowmacos / process_creation

Splunk15

RuleTypeRiskData source
Detect AzureHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect AzureHound File ModificationsTTPNULLSysmon EventID 11
Detect SharpHound Command-Line ArgumentsTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect SharpHound File ModificationsTTPNULLSysmon EventID 11
Detect SharpHound UsageTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetLocalUser with PowerShellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetLocalUser with PowerShell Script BlockHuntingNULLPowershell Script Block Logging 4104
GetWmiObject User Account with PowerShellHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
GetWmiObject User Account with PowerShell Script BlockHuntingNULLPowershell Script Block Logging 4104
Local Account Discovery with NetHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Local Account Discovery With WmicHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Network Traffic to Active Directory Web Services ProtocolHuntingNULLSysmon EventID 3
Windows Account Discovery for None Disable User AccountHuntingNULLPowershell Script Block Logging 4104
Windows SOAPHound Binary ExecutionTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows User Discovery Via NetHuntingNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2

Groups18

Software45

Show 21 more

Campaigns2

Procedure examples65

Groups18

Used byProcedure example
Groupadmin@338

admin@338 actors used the following commands following exploitation of a machine with LOWBALL malware to enumerate user accounts: net user >> %temp%\download net user /domain >> %temp%\download

GroupAPT1

APT1 used the commands net localgroup,net user, and net group to find accounts on the system.

GroupAPT3

APT3 has used a tool that can obtain info about local and global group users, power users, and administrators.

GroupAPT32

APT32 enumerated administrative users using the commands net localgroup administrators.

GroupAPT41

APT41 used built-in net commands to enumerate local administrator groups.

GroupAPT42

APT42 has used the PowerShell-based POWERPOST script to collect local account names from the victim machine.

GroupChimera

Chimera has used net user for account discovery.

GroupFox Kitten

Fox Kitten has accessed ntuser.dat and UserClass.dat on compromised hosts.

View all 18 groups examples

Software45

Used byProcedure example
MalwareAgent Tesla

Agent Tesla can collect account information from the victim’s machine.

MalwareBankshot

Bankshot gathers domain and account names/information through process monitoring.

MalwareBazar

Bazar can identify administrator accounts on an infected host.

MalwareBitPaymer

BitPaymer can enumerate the sessions for each user logged onto the infected host.

ToolBloodHound

BloodHound can identify users with local administrator rights.

MalwareComnie

Comnie uses the net user command.

MalwareDuqu

The discovery modules used with Duqu can collect information on accounts and permissions.

MalwareDUSTTRAP

DUSTTRAP can enumerate local user accounts.

View all 45 software examples

Campaigns2

Used byProcedure example
CampaignOperation CuckooBees

During Operation CuckooBees, the threat actors used the `net user` command to gather account information.

CampaignOperation Digital Eye

During Operation Digital Eye, threat actors used the local.exe tool to view local account information.

References4

  1. Crowdstrike Hypervisor Jackpotting Pt 2 2021 Open source
    Michael Dawson. (2021, August 30). Hypervisor Jackpotting, Part 2: eCrime Actors Increase Targeting of ESXi Servers with Ransomware. Retrieved March 26, 2025.
  2. Mandiant APT1 Open source
    Mandiant. (n.d.). APT1 Exposing One of China’s Cyber Espionage Units. Retrieved July 18, 2016.
  3. groups man page Open source
    MacKenzie, D. and Youngman, J. (n.d.). groups(1) - Linux man page. Retrieved January 11, 2024.
  4. id man page Open source
    MacKenzie, D. and Robbins, A. (n.d.). id(1) - Linux man page. Retrieved January 11, 2024.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.