Cross-source coverage

T1087.001 / ATT&CK

Account Discovery: Local Account

39 rules across 4 sources.

From MITRE ATT&CK 19.2

Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.

Commands such as net user and net localgroup of the Net utility and id and groups on macOS and Linux can list local users and groups. On Linux, local users can also be enumerated through the use of the /etc/passwd file. On macOS, the dscl. list /Users command can be used to enumerate local accounts. On ESXi servers, the esxcli system account list command can list local user accounts.

Tactics
Discovery
Platforms
ESXi · Linux · macOS · Windows
Telemetry
WinEventLog:Sysmonauditd:PATHlinux:Sysmonmacos:unifiedlogvpxd.logesxi:shell

How MITRE says to detect it DET0303

Local Account Enumeration Across Host Platforms

Windows Analytic 0846

Adversary enumeration of local user accounts using Net.exe, WMI, or PowerShell.

  • WinEventLog:Sysmon EventCode=1

Linux Analytic 0847

Enumeration of local users or groups via file access (/etc/passwd) or commands like id, groups.

  • auditd:PATH PATH
  • linux:Sysmon EventCode=1

macOS Analytic 0848

Enumeration of macOS local users using dscl, id, dscacheutil, or /etc/passwd access.

  • macos:unifiedlog None

ESXi Analytic 0849

Enumeration of local ESXi accounts using esxcli or vSphere API from unauthorized sessions.

  • vpxd.log vCenter Management
  • esxi:shell Shell Execution

splunk/security_content

14 rules
Detection Severity Format
Detect AzureHound Command-Line Arguments Undefined SPL
Detect AzureHound File Modifications Undefined SPL
Detect SharpHound Command-Line Arguments Undefined SPL
Detect SharpHound File Modifications Undefined SPL
Detect SharpHound Usage Undefined SPL
GetLocalUser with PowerShell Undefined SPL
GetLocalUser with PowerShell Script Block Undefined SPL
GetWmiObject User Account with PowerShell Undefined SPL
GetWmiObject User Account with PowerShell Script Block Undefined SPL
Local Account Discovery With Wmic Undefined SPL

+ 4 more from splunk/security_content → showing the 10 highest-severity

SigmaHQ/sigma

13 rules
Detection Severity Format
BloodHound Collection Files High Sigma
HackTool - Bloodhound/Sharphound Execution High Sigma
Malicious PowerShell Commandlets - PoshModule High Sigma
Malicious PowerShell Commandlets - ProcessCreation High Sigma
Malicious PowerShell Commandlets - ScriptBlock High Sigma
Suspicious Group And Account Reconnaissance Activity Using Net.EXE Medium Sigma
Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet Medium Sigma
Suspicious Use of PsLogList Medium Sigma
Cisco Collect Data Low Sigma
Local Accounts Discovery Low Sigma

+ 3 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

6 rules
Detection Severity Format
Potential Meterpreter Reverse Shell High Elastic TOML
Mounting Hidden or WebDav Remote Shares Medium Elastic TOML
Unusual User Privilege Enumeration via id Medium Elastic TOML
Enumeration of Administrator Accounts Low Elastic TOML
Enumeration of Users or Groups via Built-in Commands Low Elastic TOML
PowerShell Suspicious Discovery Related Windows API Functions Low Elastic TOML

socfortress/Wazuh-Rules

6 rules
Detection Severity Format
Account Discovery: Access to /etc/passwd detected (T1087.001) High Wazuh XML
Enumeration of local account login history using lastlog High Wazuh XML
Enumeration of user open files using lsof High Wazuh XML
UID 0 Enumeration Detected in /etc/passwd High Wazuh XML
User account or group enumeration detected (id/groups command) High Wazuh XML
Access to sudoers file detected - possible privilege enumeration Medium Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.