Cross-source coverage

T1087 / ATT&CK

Account Discovery

198 rules · 196 families across 10 sources.

1 atomic-IOC hidden · include

Showing deprecated rules · back to the default

From MITRE ATT&CK 19.2

Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts exist, which can aid in follow-on behavior such as brute-forcing, spear-phishing attacks, or account takeovers (e.g., Valid Accounts).

Adversaries may use several methods to enumerate accounts, including abuse of existing tools, built-in commands, and potential misconfigurations that leak account names and roles or permissions in the targeted environment.

For examples, cloud environments typically provide easily accessible interfaces to obtain user lists. On hosts, adversaries can use default PowerShell and other command line functionality to identify accounts. Information about email addresses and accounts may also be extracted by searching an infected system’s files.

Tactics
Discovery
Platforms
ESXi · IaaS · Identity Provider · Linux · macOS · Office Suite · SaaS · Windows
Telemetry
WinEventLog:SysmonWinEventLog:Securityauditd:SYSCALLlinux:Sysmonmacos:unifiedlogAWS:CloudTrailazure:signinlogssaas:oktaesxi:vpxdgcp:auditm365:unified

How MITRE says to detect it DET0587

Enumeration of User or Account Information Across Platforms

Windows Analytic 1612

Detection of processes performing local or domain account enumeration by invoking account directory queries or security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward.

  • WinEventLog:Sysmon EventCode=1
  • WinEventLog:Security EventCode=4688
  • WinEventLog:Security EventCode=4798, 4799

Linux Analytic 1613

Enumeration of users and groups through suspicious shell commands or unauthorized access to /etc/passwd or /etc/shadow.

  • auditd:SYSCALL PATH
  • linux:Sysmon EventCode=1

macOS Analytic 1614

Detection of account enumeration through directory service queries or system utilities accessing account metadata stores, followed by structured enumeration output.

  • macos:unifiedlog process event
  • macos:unifiedlog DirectoryService queries retrieving account information

IaaS Analytic 1615

Detection of enumeration of identity entities through cloud provider APIs where principals retrieve account metadata such as IAM users or roles in rapid succession.

  • AWS:CloudTrail DescribeUsers / ListUsers / GetUser

Identity Provider Analytic 1616

Detection of identity directory enumeration through API calls or administrative queries retrieving multiple account objects within a short interval.

  • azure:signinlogs Graph API Query
  • saas:okta User Enumeration Events

ESXi Analytic 1617

Detection of enumeration activity when system processes query ESXi host account configuration or management APIs to retrieve user account listings.

  • esxi:vpxd vCenter Management

SaaS Analytic 1618

Account enumeration via bulk access to user directory features or hidden APIs.

  • gcp:audit Directory API Access

Office Suite Analytic 1619

Account discovery via VBA macros, COM objects, or embedded scripting.

  • m365:unified Scripted Activity

Sub-techniques with coverage

Counted in the 198 above — a rule tagged a sub-technique covers this technique too.


socfortress/Wazuh-Rules

42 rules · 41 families
Detection Severity Format
Account Discovery: Access to /etc/passwd detected (T1087.001) High Wazuh XML
Enumeration of local account login history using lastlog High Wazuh XML
Enumeration of user open files using lsof High Wazuh XML
LDAP domain account enumeration attempt detected using ldapsearch (T1087.002) High Wazuh XML
operation. · office_365.LogonError = PassThroughUserMfaError High Wazuh XML
operation. · office_365.LogonError = UnauthorizedClientDoesNotMatchRequest High Wazuh XML
Possible domain account enumeration using ldapdomaindump High Wazuh XML
Powershell script: Active Directory enumeration detected High Wazuh XML
Sysmon - Event 1: Process creation · AdFind Execution (T1087.002) High Wazuh XML
Sysmon - Event 1: Process creation · ADRecon.ps1 Execution (T1087.002) High Wazuh XML

+ 32 more from socfortress/Wazuh-Rules → showing the 10 highest-severity

splunk/security_content

42 rules
Detection Severity Format
AdsiSearcher Account Discovery Undefined SPL
Azure AD AzureHound UserAgent Detected Undefined SPL
Azure AD Service Principal Enumeration Undefined SPL
Detect AzureHound Command-Line Arguments Undefined SPL
Detect AzureHound File Modifications Undefined SPL
Detect SharpHound Command-Line Arguments Undefined SPL
Detect SharpHound File Modifications Undefined SPL
Detect SharpHound Usage Undefined SPL
Domain Account Discovery with Dsquery Undefined SPL
Domain Account Discovery with Wmic Undefined SPL

+ 32 more from splunk/security_content → showing the 10 highest-severity

SigmaHQ/sigma

41 rules
Detection Severity Format
AD Privileged Users or Groups Reconnaissance High Sigma
BloodHound Collection Files High Sigma
Chopper Webshell Process Pattern High Sigma
Discovery Using AzureHound High Sigma
HackTool - Bloodhound/Sharphound Execution High Sigma
Hacktool Ruler High Sigma
HackTool - SOAPHound Execution High Sigma
HackTool - winPEAS Execution High Sigma
Malicious PowerShell Commandlets - PoshModule High Sigma
Malicious PowerShell Commandlets - ProcessCreation High Sigma

+ 31 more from SigmaHQ/sigma → showing the 10 highest-severity

elastic/detection-rules

29 rules
Detection Severity Format
Azure AD Graph Access with Suspicious User-Agent High Elastic TOML
Azure AD Graph Potential Enumeration (ROADrecon) High Elastic TOML
Entra ID OAuth Device Code Sign-in to Azure AD Graph Enumeration High Elastic TOML
Entra ID Sign-in BloodHound Suite User-Agent Detected High Elastic TOML
Entra ID Sign-in TeamFiltration User-Agent Detected High Elastic TOML
Potential Meterpreter Reverse Shell High Elastic TOML
AWS EC2 Role GetCallerIdentity from New Source AS Organization Medium Elastic TOML
AWS IAM Principal Enumeration via UpdateAssumeRolePolicy Medium Elastic TOML
AWS STS GetCallerIdentity API Called for the First Time Medium Elastic TOML
Azure AD Graph Access with Unusual Client and User Medium Elastic TOML

+ 19 more from elastic/detection-rules → showing the 10 highest-severity

elastic/protections-artifacts

12 rules
Detection Severity Format
Active Directory Data Collection via LDAP Undefined Elastic TOML
AD Certificate Services Enumeration via LDAP Undefined Elastic TOML
Domain Accounts Enumeration via LDAP Search Undefined Elastic TOML
Domain Computers Enumeration via LDAP Search Undefined Elastic TOML
Domain Password Policy Enumeration via LDAP Undefined Elastic TOML
Domain Trust and Schema Enumeration via LDAP Undefined Elastic TOML
Group and Privileged Accounts Discovery via LDAP Undefined Elastic TOML
Password Spraying Enumeration via LDAP Undefined Elastic TOML
Privileged Domain Group Enumeration via LDAP Undefined Elastic TOML
Sensitive Attributes Discovery via LDAP Undefined Elastic TOML

+ 2 more from elastic/protections-artifacts → showing the 10 highest-severity

Bert-JanP/Hunting-Queries-Detection-Rules

8 rules · 7 families
Detection Severity Format
Anomalous Amount of LDAP traffic Undefined KQL
AzureHound Detection 2 variants Undefined KQL
AzureHound Detection 2 variants Undefined KQL
Detect net(1).exe Discovery Activities Undefined KQL
Encoded Powershell Commands That Have Potentially Performed Recon Activities Undefined KQL
List net(1).exe discovery activities Undefined KQL
MITRE ATT&CK Mapping Undefined KQL
Operation download all users in Azure Active directory performed Undefined KQL

panther-labs/panther-analysis

8 rules
Detection Severity Format
Anthropic Excessive Chat Access Failures Medium Panther Python
AppOmni Alert Passthrough Medium Panther Python
AWS STS GetCallerIdentity via TruffleHog Medium Panther Python
Azure Key Vault Key Accessed or Recovered Medium Panther Python
Databricks Repeated Unauthorized Unity Catalog Requests Medium Panther Python
GSuite Calendar Has Been Made Public Medium Panther Python
GSuite Workspace Calendar External Sharing Setting Change Medium Panther Python
AWS CloudTrail Account Discovery Informational Panther Python

chronicle/detection-rules

6 rules
Detection Severity Format
hacktool_purpleknight_execution Medium YARA-L
account_discovery_activity_detector_sysmon_behavior Undefined YARA-L
ad_privileged_users_or_groups_reconnaissance Undefined YARA-L
detect_enumeration_via_wmi Undefined YARA-L
hacktool_use Undefined YARA-L
hostdomain_enumeration_with_wmic Undefined YARA-L

Azure/Azure-Sentinel

5 rules
Detection Severity Format
Rare domains seen in Cloud Logs Undefined KQL
Same User - Successful logon for a given App and failure on another App within 1m and low distribution Undefined KQL
Successful Sign-In From Non-Compliant Device with bulk download activity Undefined KQL
Suspicious enumeration using Adfind tool (Normalized Process Events) Undefined KQL
Tracking Privileged Account Rare Activity Undefined KQL

Wazuh Core Ruleset

5 rules
Detection Severity Format
A net.exe account discovery command was initiated Low Wazuh XML
Discovery activity executed Low Wazuh XML
Discovery activity spawned via powershell execution Low Wazuh XML
Powershell script "Get-NetUser executed". Low Wazuh XML
Suspicious Windows cmd shell execution Low Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.