Cross-source coverage
T1069.001 / ATT&CK
Permission Groups Discovery: Local Groups
40 rules across 5 sources.
From MITRE ATT&CK 19.2
Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.
Commands such as net localgroup of the Net utility, dscl. -list /Groups on macOS, and groups on Linux can list local groups.
- Tactics
- Discovery
- Platforms
- Linux · macOS · Windows
- Telemetry
-
WinEventLog:Securityauditd:SYSCALLmacos:unifiedlog
How MITRE says to detect it DET0114
Behavioral Detection of Local Group Enumeration Across OS Platforms
Windows Analytic 0317
Detects attempts to enumerate local groups via Net.exe, PowerShell, or native API calls that precede lateral movement or privilege abuse.
WinEventLog:SecurityEventCode=4688
Linux Analytic 0318
Detects enumeration of local groups using common binaries (groups, getent, cat /etc/group) or scripting with suspicious lineage.
auditd:SYSCALLexecve
macOS Analytic 0319
Detects use of dscl or id/group commands to enumerate local system groups, often by post-exploitation tools or persistence checks.
macos:unifiedlogprocess:exec
SigmaHQ/sigma
16 rules| Detection | Severity | Format |
|---|---|---|
| BloodHound Collection Files | High | Sigma |
| HackTool - Bloodhound/Sharphound Execution | High | Sigma |
| Malicious PowerShell Commandlets - PoshModule | High | Sigma |
| Malicious PowerShell Commandlets - ProcessCreation | High | Sigma |
| Malicious PowerShell Commandlets - ScriptBlock | High | Sigma |
| Permission Check Via Accesschk.EXE | Medium | Sigma |
| AD Groups Or Users Enumeration Using PowerShell - PoshModule | Low | Sigma |
| AD Groups Or Users Enumeration Using PowerShell - ScriptBlock | Low | Sigma |
| Local Groups Discovery - Linux | Low | Sigma |
| Local Groups Reconnaissance Via Wmic.EXE | Low | Sigma |
+ 6 more from SigmaHQ/sigma → showing the 10 highest-severity
splunk/security_content
14 rules| Detection | Severity | Format |
|---|---|---|
| Detect AzureHound Command-Line Arguments | Undefined | SPL |
| Detect AzureHound File Modifications | Undefined | SPL |
| Detect SharpHound Command-Line Arguments | Undefined | SPL |
| Detect SharpHound File Modifications | Undefined | SPL |
| Detect SharpHound Usage | Undefined | SPL |
| Get WMIObject Group Discovery | Undefined | SPL |
| Get WMIObject Group Discovery with Script Block Logging | Undefined | SPL |
| Network Traffic to Active Directory Web Services Protocol | Undefined | SPL |
| PowerShell Get LocalGroup Discovery | Undefined | SPL |
| Powershell Get LocalGroup Discovery with Script Block Logging | Undefined | SPL |
+ 4 more from splunk/security_content → showing the 10 highest-severity
elastic/detection-rules
6 rules| Detection | Severity | Format |
|---|---|---|
| Enumeration of Privileged Local Groups Membership | Medium | Elastic TOML |
| Unusual User Privilege Enumeration via id | Medium | Elastic TOML |
| Enumeration of Administrator Accounts | Low | Elastic TOML |
| Enumeration of Users or Groups via Built-in Commands | Low | Elastic TOML |
| PowerShell Suspicious Discovery Related Windows API Functions | Low | Elastic TOML |
| Sudo Command Enumeration Detected | Low | Elastic TOML |
Bert-JanP/Hunting-Queries-Detection-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Local Group Discovery | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
socfortress/Wazuh-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Powershell script: Local group enumeration detected | High | Wazuh XML |
| Permission Groups Discovery - Possible local group enumeration activity detected | Medium | Wazuh XML |