System Owner or User Discovery - Linux
Description
Detects the execution of host or user discovery utilities such as "whoami", "hostname", "id", etc. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Query · sigma
selection: type: EXECVE a0: - hostname - id - last - uname - users - w - who - whoami condition: selection
Known false positives
- Admin activity