Cross-source coverage
T1087 / ATT&CK
Account Discovery
From MITRE ATT&CK 19.2
Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts exist, which can aid in follow-on behavior such as brute-forcing, spear-phishing attacks, or account takeovers (e.g., Valid Accounts).
Adversaries may use several methods to enumerate accounts, including abuse of existing tools, built-in commands, and potential misconfigurations that leak account names and roles or permissions in the targeted environment.
For examples, cloud environments typically provide easily accessible interfaces to obtain user lists. On hosts, adversaries can use default PowerShell and other command line functionality to identify accounts. Information about email addresses and accounts may also be extracted by searching an infected system’s files.
- Tactics
- Discovery
- Platforms
- ESXi · IaaS · Identity Provider · Linux · macOS · Office Suite · SaaS · Windows
- Telemetry
-
WinEventLog:SysmonWinEventLog:Securityauditd:SYSCALLlinux:Sysmonmacos:unifiedlogAWS:CloudTrailazure:signinlogssaas:oktaesxi:vpxdgcp:auditm365:unified
How MITRE says to detect it DET0587
Enumeration of User or Account Information Across Platforms
Windows Analytic 1612
Detection of processes performing local or domain account enumeration by invoking account directory queries or security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward.
WinEventLog:SysmonEventCode=1WinEventLog:SecurityEventCode=4688WinEventLog:SecurityEventCode=4798, 4799
Linux Analytic 1613
Enumeration of users and groups through suspicious shell commands or unauthorized access to /etc/passwd or /etc/shadow.
auditd:SYSCALLPATHlinux:SysmonEventCode=1
macOS Analytic 1614
Detection of account enumeration through directory service queries or system utilities accessing account metadata stores, followed by structured enumeration output.
macos:unifiedlogprocess eventmacos:unifiedlogDirectoryService queries retrieving account information
IaaS Analytic 1615
Detection of enumeration of identity entities through cloud provider APIs where principals retrieve account metadata such as IAM users or roles in rapid succession.
AWS:CloudTrailDescribeUsers / ListUsers / GetUser
Identity Provider Analytic 1616
Detection of identity directory enumeration through API calls or administrative queries retrieving multiple account objects within a short interval.
azure:signinlogsGraph API Querysaas:oktaUser Enumeration Events
ESXi Analytic 1617
Detection of enumeration activity when system processes query ESXi host account configuration or management APIs to retrieve user account listings.
esxi:vpxdvCenter Management
SaaS Analytic 1618
Account enumeration via bulk access to user directory features or hidden APIs.
gcp:auditDirectory API Access
Office Suite Analytic 1619
Account discovery via VBA macros, COM objects, or embedded scripting.
m365:unifiedScripted Activity
Sub-techniques with coverage
Counted in the 193 above — a rule tagged a sub-technique covers this technique too.
socfortress/Wazuh-Rules
42 rules · 41 families| Detection | Severity | Format |
|---|---|---|
| Account Discovery: Access to /etc/passwd detected (T1087.001) | High | Wazuh XML |
| Enumeration of local account login history using lastlog | High | Wazuh XML |
| Enumeration of user open files using lsof | High | Wazuh XML |
| LDAP domain account enumeration attempt detected using ldapsearch (T1087.002) | High | Wazuh XML |
| operation. · office_365.LogonError = PassThroughUserMfaError | High | Wazuh XML |
| operation. · office_365.LogonError = UnauthorizedClientDoesNotMatchRequest | High | Wazuh XML |
| Possible domain account enumeration using ldapdomaindump | High | Wazuh XML |
| Powershell script: Active Directory enumeration detected | High | Wazuh XML |
| Sysmon - Event 1: Process creation · AdFind Execution (T1087.002) | High | Wazuh XML |
| Sysmon - Event 1: Process creation · ADRecon.ps1 Execution (T1087.002) | High | Wazuh XML |
+ 32 more from socfortress/Wazuh-Rules → showing the 10 highest-severity
splunk/security_content
42 rules| Detection | Severity | Format |
|---|---|---|
| AdsiSearcher Account Discovery | Undefined | SPL |
| Azure AD AzureHound UserAgent Detected | Undefined | SPL |
| Azure AD Service Principal Enumeration | Undefined | SPL |
| Detect AzureHound Command-Line Arguments | Undefined | SPL |
| Detect AzureHound File Modifications | Undefined | SPL |
| Detect SharpHound Command-Line Arguments | Undefined | SPL |
| Detect SharpHound File Modifications | Undefined | SPL |
| Detect SharpHound Usage | Undefined | SPL |
| Domain Account Discovery with Dsquery | Undefined | SPL |
| Domain Account Discovery with Wmic | Undefined | SPL |
+ 32 more from splunk/security_content → showing the 10 highest-severity
SigmaHQ/sigma
41 rules| Detection | Severity | Format |
|---|---|---|
| AD Privileged Users or Groups Reconnaissance | High | Sigma |
| BloodHound Collection Files | High | Sigma |
| Chopper Webshell Process Pattern | High | Sigma |
| Discovery Using AzureHound | High | Sigma |
| HackTool - Bloodhound/Sharphound Execution | High | Sigma |
| Hacktool Ruler | High | Sigma |
| HackTool - SOAPHound Execution | High | Sigma |
| HackTool - winPEAS Execution | High | Sigma |
| Malicious PowerShell Commandlets - PoshModule | High | Sigma |
| Malicious PowerShell Commandlets - ProcessCreation | High | Sigma |
+ 31 more from SigmaHQ/sigma → showing the 10 highest-severity
elastic/detection-rules
29 rules| Detection | Severity | Format |
|---|---|---|
| Azure AD Graph Access with Suspicious User-Agent | High | Elastic TOML |
| Azure AD Graph Potential Enumeration (ROADrecon) | High | Elastic TOML |
| Entra ID OAuth Device Code Sign-in to Azure AD Graph Enumeration | High | Elastic TOML |
| Entra ID Sign-in BloodHound Suite User-Agent Detected | High | Elastic TOML |
| Entra ID Sign-in TeamFiltration User-Agent Detected | High | Elastic TOML |
| Potential Meterpreter Reverse Shell | High | Elastic TOML |
| AWS EC2 Role GetCallerIdentity from New Source AS Organization | Medium | Elastic TOML |
| AWS IAM Principal Enumeration via UpdateAssumeRolePolicy | Medium | Elastic TOML |
| AWS STS GetCallerIdentity API Called for the First Time | Medium | Elastic TOML |
| Azure AD Graph Access with Unusual Client and User | Medium | Elastic TOML |
+ 19 more from elastic/detection-rules → showing the 10 highest-severity
elastic/protections-artifacts
12 rules| Detection | Severity | Format |
|---|---|---|
| Active Directory Data Collection via LDAP | Undefined | Elastic TOML |
| AD Certificate Services Enumeration via LDAP | Undefined | Elastic TOML |
| Domain Accounts Enumeration via LDAP Search | Undefined | Elastic TOML |
| Domain Computers Enumeration via LDAP Search | Undefined | Elastic TOML |
| Domain Password Policy Enumeration via LDAP | Undefined | Elastic TOML |
| Domain Trust and Schema Enumeration via LDAP | Undefined | Elastic TOML |
| Group and Privileged Accounts Discovery via LDAP | Undefined | Elastic TOML |
| Password Spraying Enumeration via LDAP | Undefined | Elastic TOML |
| Privileged Domain Group Enumeration via LDAP | Undefined | Elastic TOML |
| Sensitive Attributes Discovery via LDAP | Undefined | Elastic TOML |
+ 2 more from elastic/protections-artifacts → showing the 10 highest-severity
Bert-JanP/Hunting-Queries-Detection-Rules
8 rules · 7 families| Detection | Severity | Format |
|---|---|---|
| Anomalous Amount of LDAP traffic | Undefined | KQL |
| AzureHound Detection 2 variants | Undefined | KQL |
| AzureHound Detection 2 variants | Undefined | KQL |
| Detect net(1).exe Discovery Activities | Undefined | KQL |
| Encoded Powershell Commands That Have Potentially Performed Recon Activities | Undefined | KQL |
| List net(1).exe discovery activities | Undefined | KQL |
| MITRE ATT&CK Mapping | Undefined | KQL |
| Operation download all users in Azure Active directory performed | Undefined | KQL |
panther-labs/panther-analysis
8 rules| Detection | Severity | Format |
|---|---|---|
| Anthropic Excessive Chat Access Failures | Medium | Panther Python |
| AppOmni Alert Passthrough | Medium | Panther Python |
| AWS STS GetCallerIdentity via TruffleHog | Medium | Panther Python |
| Azure Key Vault Key Accessed or Recovered | Medium | Panther Python |
| Databricks Repeated Unauthorized Unity Catalog Requests | Medium | Panther Python |
| GSuite Calendar Has Been Made Public | Medium | Panther Python |
| GSuite Workspace Calendar External Sharing Setting Change | Medium | Panther Python |
| AWS CloudTrail Account Discovery | Informational | Panther Python |
Azure/Azure-Sentinel
5 rules| Detection | Severity | Format |
|---|---|---|
| Rare domains seen in Cloud Logs | Undefined | KQL |
| Same User - Successful logon for a given App and failure on another App within 1m and low distribution | Undefined | KQL |
| Successful Sign-In From Non-Compliant Device with bulk download activity | Undefined | KQL |
| Suspicious enumeration using Adfind tool (Normalized Process Events) | Undefined | KQL |
| Tracking Privileged Account Rare Activity | Undefined | KQL |
Wazuh Core Ruleset
5 rules| Detection | Severity | Format |
|---|---|---|
| A net.exe account discovery command was initiated | Low | Wazuh XML |
| Discovery activity executed | Low | Wazuh XML |
| Discovery activity spawned via powershell execution | Low | Wazuh XML |
| Powershell script "Get-NetUser executed". | Low | Wazuh XML |
| Suspicious Windows cmd shell execution | Low | Wazuh XML |
chronicle/detection-rules
1 rule| Detection | Severity | Format |
|---|---|---|
| hacktool_purpleknight_execution | Medium | YARA-L |