System Owner or User Discovery - Linux

 Original Source: [Sigma source]
Title: System Owner or User Discovery - Linux
Status: test
Description:Detects the execution of host or user discovery utilities such as "whoami", "hostname", "id", etc. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
References:
  -https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1033/T1033.md
Author: Timur Zinniatullin, oscd.community
Date: 2019-10-21
modified:2025-06-04
Tags:
  • -'attack.discovery'
  • -'attack.t1033'
Logsource:
  • product: linux
  • service: auditd
Detection:
  selection:
    type: 'EXECVE'
    a0:
      -'hostname'
      -'id'
      -'last'
      -'uname'
      -'users'
      -'w'
      -'who'
      -'whoami'

  condition:selection
Falsepositives:
  -Admin activity
Level: low