Cross-source coverage
T1087.001 / ATT&CK
Account Discovery: Local Account
39 rules across 4 sources.
From MITRE ATT&CK 19.2
Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.
Commands such as net user and net localgroup of the Net utility and id and groups on macOS and Linux can list local users and groups. On Linux, local users can also be enumerated through the use of the /etc/passwd file. On macOS, the dscl. list /Users command can be used to enumerate local accounts. On ESXi servers, the esxcli system account list command can list local user accounts.
- Tactics
- Discovery
- Platforms
- ESXi · Linux · macOS · Windows
- Telemetry
-
WinEventLog:Sysmonauditd:PATHlinux:Sysmonmacos:unifiedlogvpxd.logesxi:shell
How MITRE says to detect it DET0303
Local Account Enumeration Across Host Platforms
Windows Analytic 0846
Adversary enumeration of local user accounts using Net.exe, WMI, or PowerShell.
WinEventLog:SysmonEventCode=1
Linux Analytic 0847
Enumeration of local users or groups via file access (/etc/passwd) or commands like id, groups.
auditd:PATHPATHlinux:SysmonEventCode=1
macOS Analytic 0848
Enumeration of macOS local users using dscl, id, dscacheutil, or /etc/passwd access.
macos:unifiedlogNone
ESXi Analytic 0849
Enumeration of local ESXi accounts using esxcli or vSphere API from unauthorized sessions.
vpxd.logvCenter Managementesxi:shellShell Execution
splunk/security_content
14 rules| Detection | Severity | Format |
|---|---|---|
| Detect AzureHound Command-Line Arguments | Undefined | SPL |
| Detect AzureHound File Modifications | Undefined | SPL |
| Detect SharpHound Command-Line Arguments | Undefined | SPL |
| Detect SharpHound File Modifications | Undefined | SPL |
| Detect SharpHound Usage | Undefined | SPL |
| GetLocalUser with PowerShell | Undefined | SPL |
| GetLocalUser with PowerShell Script Block | Undefined | SPL |
| GetWmiObject User Account with PowerShell | Undefined | SPL |
| GetWmiObject User Account with PowerShell Script Block | Undefined | SPL |
| Local Account Discovery With Wmic | Undefined | SPL |
+ 4 more from splunk/security_content → showing the 10 highest-severity
SigmaHQ/sigma
13 rules| Detection | Severity | Format |
|---|---|---|
| BloodHound Collection Files | High | Sigma |
| HackTool - Bloodhound/Sharphound Execution | High | Sigma |
| Malicious PowerShell Commandlets - PoshModule | High | Sigma |
| Malicious PowerShell Commandlets - ProcessCreation | High | Sigma |
| Malicious PowerShell Commandlets - ScriptBlock | High | Sigma |
| Suspicious Group And Account Reconnaissance Activity Using Net.EXE | Medium | Sigma |
| Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet | Medium | Sigma |
| Suspicious Use of PsLogList | Medium | Sigma |
| Cisco Collect Data | Low | Sigma |
| Local Accounts Discovery | Low | Sigma |
+ 3 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
6 rules| Detection | Severity | Format |
|---|---|---|
| Potential Meterpreter Reverse Shell | High | Elastic TOML |
| Mounting Hidden or WebDav Remote Shares | Medium | Elastic TOML |
| Unusual User Privilege Enumeration via id | Medium | Elastic TOML |
| Enumeration of Administrator Accounts | Low | Elastic TOML |
| Enumeration of Users or Groups via Built-in Commands | Low | Elastic TOML |
| PowerShell Suspicious Discovery Related Windows API Functions | Low | Elastic TOML |
socfortress/Wazuh-Rules
6 rules| Detection | Severity | Format |
|---|---|---|
| Account Discovery: Access to /etc/passwd detected (T1087.001) | High | Wazuh XML |
| Enumeration of local account login history using lastlog | High | Wazuh XML |
| Enumeration of user open files using lsof | High | Wazuh XML |
| UID 0 Enumeration Detected in /etc/passwd | High | Wazuh XML |
| User account or group enumeration detected (id/groups command) | High | Wazuh XML |
| Access to sudoers file detected - possible privilege enumeration | Medium | Wazuh XML |