T1589.003 — Employee Names
T1589.003: Employee Names
MITRE ATT&CK® Enterprise technique
| Tactics | Reconnaissance |
| Platforms | PRE |
| Permissions required | — |
| Version | 1.0 |
| Parent technique | T1589 |
Description
Adversaries may gather employee names that can be used during targeting. Employee names be used to derive email addresses as well as to help guide other reconnaissance efforts and/or craft more-believable lures.
Adversaries may easily gather employee names, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites).(Citation: OPM Leak) Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Compromise Accounts), and/or initial access (ex: Phishing or Valid Accounts).
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1589/003
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/