T1087.001 Local Account
Sub-technique of T1087 Account Discovery
Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior. Commands such as net user and net localgroup of the [Net](https://attack.mitre.org/software/S0039) utility and id and groups on macOS and Linux can list local users and groups.(Citation: Mandiant APT1)(Citation: id…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- BloodHound Collection Fileshightest · windows
- HackTool - Bloodhound/Sharphound Executionhightest · windows
- Malicious PowerShell Commandlets - PoshModulehightest · windows
- Malicious PowerShell Commandlets - ProcessCreationhightest · windows
- Malicious PowerShell Commandlets - ScriptBlockhightest · windows
- Suspicious Group And Account Reconnaissance Activity Using Net.EXEmediumtest · windows
- Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdletmediumtest · windows
- Suspicious Use of PsLogListmediumtest · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.