T1589 Gather Victim Identity Information
Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, security question responses, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations. Adversaries may gather this…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Azure AD Account Credential Leakedhightest · azure
- SSHD Error Message CVE-2018-15473mediumtest · linux
- Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlockmediumexperimental · windows
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.