Technique with 4 sub-techniques.View on attack.mitre.org
Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts exist, which can aid in follow-on behavior such as brute-forcing, spear-phishing attacks, or account takeovers (e.g., Valid Accounts).
Adversaries may use several methods to enumerate accounts, including abuse of existing tools, built-in commands, and potential misconfigurations that leak account names and roles or permissions in the targeted environment.
For examples, cloud environments typically provide easily accessible interfaces to obtain user lists. On hosts, adversaries can use default PowerShell and other command line functionality to identify accounts. Information about email addresses and accounts may also be extracted by searching an infected system’s files.
Rules on DetectionCode tagged with T1087 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Account Discovery With Net App | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.002 |
| AdsiSearcher Account Discovery | TTP | NULL | Powershell Script Block Logging 4104 | T1087.002 |
| Azure AD AzureHound UserAgent Detected | TTP | NULL | Azure Active Directory NonInteractiveUserSignInLogs, Azure Active Directory MicrosoftGraphActivityLogs | T1087.004 |
| Azure AD Service Principal Enumeration | TTP | NULL | Azure Active Directory MicrosoftGraphActivityLogs | T1087.004 |
| Detect AzureHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.001 T1087.002 |
| Detect AzureHound File Modifications | TTP | NULL | Sysmon EventID 11 | T1087.001 T1087.002 |
| Detect SharpHound Command-Line Arguments | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.001 T1087.002 |
| Detect SharpHound File Modifications | TTP | NULL | Sysmon EventID 11 | T1087.001 T1087.002 |
| Detect SharpHound Usage | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.001 T1087.002 |
| Domain Account Discovery with Dsquery | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.002 |
| Domain Account Discovery With Net App | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.002 |
| Domain Account Discovery with Wmic | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.002 |
| Enumerate Users Local Group Using Telegram | TTP | NULL | Windows Event Log Security 4798 | T1087 |
| Get ADUser with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.002 |
| Get ADUser with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 | T1087.002 |
| Get DomainUser with PowerShell | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.002 |
| Get DomainUser with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 | T1087.002 |
| GetLocalUser with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.001 |
| GetLocalUser with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 | T1087.001 |
| GetWmiObject DS User with PowerShell | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.002 |
| GetWmiObject DS User with PowerShell Script Block | TTP | NULL | Powershell Script Block Logging 4104 | T1087.002 |
| GetWmiObject User Account with PowerShell | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.001 |
| GetWmiObject User Account with PowerShell Script Block | Hunting | NULL | Powershell Script Block Logging 4104 | T1087.001 |
| Local Account Discovery with Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.001 |
| Local Account Discovery With Wmic | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.001 |
| Network Traffic to Active Directory Web Services Protocol | Hunting | NULL | Sysmon EventID 3 | T1087.001 T1087.002 |
| Okta IDP Lifecycle Modifications | Anomaly | NULL | Okta | T1087.004 |
| Okta Unauthorized Access to Application | Anomaly | NULL | Okta | T1087.004 |
| SchCache Change By App Connect And Create ADSI Object | Anomaly | NULL | Sysmon EventID 11 | T1087.002 |
| Windows Account Discovery for None Disable User Account | Hunting | NULL | Powershell Script Block Logging 4104 | T1087.001 |
| Windows Account Discovery for Sam Account Name | Anomaly | NULL | Powershell Script Block Logging 4104 | T1087 |
| Windows Account Discovery With NetUser PreauthNotRequire | Hunting | NULL | Powershell Script Block Logging 4104 | T1087 |
| Windows AD Abnormal Object Access Activity | Anomaly | NULL | Windows Event Log Security 4662 | T1087.002 |
| Windows AD Privileged Object Access Activity | TTP | NULL | Windows Event Log Security 4662 | T1087.002 |
| Windows Domain Account Discovery Via Get-NetComputer | Anomaly | NULL | Powershell Script Block Logging 4104 | T1087.002 |
| Windows Find Domain Organizational Units with GetDomainOU | TTP | NULL | Powershell Script Block Logging 4104 | T1087.002 |
| Windows Find Interesting ACL with FindInterestingDomainAcl | TTP | NULL | Powershell Script Block Logging 4104 | T1087.002 |
| Windows Forest Discovery with GetForestDomain | TTP | NULL | Powershell Script Block Logging 4104 | T1087.002 |
| Windows Get Local Admin with FindLocalAdminAccess | TTP | NULL | Powershell Script Block Logging 4104 | T1087.002 |
| Windows Linked Policies In ADSI Discovery | Anomaly | NULL | Powershell Script Block Logging 4104 | T1087.002 |
| Windows Root Domain linked policies Discovery | Anomaly | NULL | Powershell Script Block Logging 4104 | T1087.002 |
| Windows SOAPHound Binary Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.001 T1087.002 |
| Windows Special Privileged Logon On Multiple Hosts | TTP | NULL | Windows Event Log Security 4672 | T1087 |
| Windows Suspect Process With Authentication Traffic | Anomaly | NULL | Sysmon EventID 3 | T1087.002 |
| Windows User Discovery Via Net | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1087.001 T1087.002 |
| Used by | Procedure example |
|---|---|
| GroupAquatic Panda | Aquatic Panda used the |
| GroupFIN13 | FIN13 has enumerated all users and their roles from a victim's main treasury system. |
| GroupScattered Spider | Scattered Spider has identified vSphere administrator accounts. |
| Used by | Procedure example |
|---|---|
| MalwareHavoc | Havoc can identify privileged user accounts on infected systems. |
| ToolShimRatReporter | ShimRatReporter listed all non-privileged and privileged accounts available on the machine. |
| MalwareTONESHELL | TONESHELL included functionality to retrieve a list of user accounts. |
| MalwareWoody RAT | Woody RAT can identify administrator accounts on an infected machine. |
| MalwareXCSSET | XCSSET attempts to discover accounts from various locations such as a user's Evernote, AppleID, Telegram, Skype, and WeChat data. |
| Used by | Procedure example |
|---|---|
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to query internal database user account tables to enumerate accounts and identify high-privilege accounts within compromised environments. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 obtained a list of users and their roles from an Exchange server using `Get-ManagementRoleAssignment`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.