Cross-source coverage

T1069.001 / ATT&CK

Permission Groups Discovery: Local Groups

40 rules across 5 sources.

From MITRE ATT&CK 19.2

Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.

Commands such as net localgroup of the Net utility, dscl. -list /Groups on macOS, and groups on Linux can list local groups.

Tactics
Discovery
Platforms
Linux · macOS · Windows
Telemetry
WinEventLog:Securityauditd:SYSCALLmacos:unifiedlog

How MITRE says to detect it DET0114

Behavioral Detection of Local Group Enumeration Across OS Platforms

Windows Analytic 0317

Detects attempts to enumerate local groups via Net.exe, PowerShell, or native API calls that precede lateral movement or privilege abuse.

  • WinEventLog:Security EventCode=4688

Linux Analytic 0318

Detects enumeration of local groups using common binaries (groups, getent, cat /etc/group) or scripting with suspicious lineage.

  • auditd:SYSCALL execve

macOS Analytic 0319

Detects use of dscl or id/group commands to enumerate local system groups, often by post-exploitation tools or persistence checks.

  • macos:unifiedlog process:exec

SigmaHQ/sigma

16 rules
Detection Severity Format
BloodHound Collection Files High Sigma
HackTool - Bloodhound/Sharphound Execution High Sigma
Malicious PowerShell Commandlets - PoshModule High Sigma
Malicious PowerShell Commandlets - ProcessCreation High Sigma
Malicious PowerShell Commandlets - ScriptBlock High Sigma
Permission Check Via Accesschk.EXE Medium Sigma
AD Groups Or Users Enumeration Using PowerShell - PoshModule Low Sigma
AD Groups Or Users Enumeration Using PowerShell - ScriptBlock Low Sigma
Local Groups Discovery - Linux Low Sigma
Local Groups Reconnaissance Via Wmic.EXE Low Sigma

+ 6 more from SigmaHQ/sigma → showing the 10 highest-severity

splunk/security_content

14 rules
Detection Severity Format
Detect AzureHound Command-Line Arguments Undefined SPL
Detect AzureHound File Modifications Undefined SPL
Detect SharpHound Command-Line Arguments Undefined SPL
Detect SharpHound File Modifications Undefined SPL
Detect SharpHound Usage Undefined SPL
Get WMIObject Group Discovery Undefined SPL
Get WMIObject Group Discovery with Script Block Logging Undefined SPL
Network Traffic to Active Directory Web Services Protocol Undefined SPL
PowerShell Get LocalGroup Discovery Undefined SPL
Powershell Get LocalGroup Discovery with Script Block Logging Undefined SPL

+ 4 more from splunk/security_content → showing the 10 highest-severity

elastic/detection-rules

6 rules
Detection Severity Format
Enumeration of Privileged Local Groups Membership Medium Elastic TOML
Unusual User Privilege Enumeration via id Medium Elastic TOML
Enumeration of Administrator Accounts Low Elastic TOML
Enumeration of Users or Groups via Built-in Commands Low Elastic TOML
PowerShell Suspicious Discovery Related Windows API Functions Low Elastic TOML
Sudo Command Enumeration Detected Low Elastic TOML

Bert-JanP/Hunting-Queries-Detection-Rules

2 rules
Detection Severity Format
Local Group Discovery Undefined KQL
MITRE ATT&CK Mapping Undefined KQL

socfortress/Wazuh-Rules

2 rules
Detection Severity Format
Powershell script: Local group enumeration detected High Wazuh XML
Permission Groups Discovery - Possible local group enumeration activity detected Medium Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.