Cybersecurity from Málaga · Networks, lures and threats

← Threats
MITRE ATT&CK technique · Discovery

T1033 System Owner/User Discovery

Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using [OS Credential Dumping](https://attack.mitre.org/techniques/T1003). The information may be collected in a number of different ways using other Discovery…

MITRE ATT&CK page ↗

Who uses it · with stories on Jábega

Sigma rules to hunt it

Showing 25 of 26.

Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.