Umbra Wiki technique technique/T1087.001
Back to wiki

T1087.001 — Local Account

provenance: imported · ATT&CK: T1087.001

T1087.001: Local Account

MITRE ATT&CK® Enterprise technique

Tactics Discovery
Platforms ESXi, Linux, macOS, Windows
Permissions required
Version 1.5
Parent technique T1087

Description

Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.

Commands such as <code>net user</code> and <code>net localgroup</code> of the Net utility and <code>id</code> and <code>groups</code> on macOS and Linux can list local users and groups.(Citation: Mandiant APT1)(Citation: id man page)(Citation: groups man page) On Linux, local users can also be enumerated through the use of the <code>/etc/passwd</code> file. On macOS, the <code>dscl . list /Users</code> command can be used to enumerate local accounts. On ESXi servers, the esxcli system account list command can list local user accounts.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1087/001
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/