FORENSIA

ATT&CK · T1033

System Owner/User Discovery

Tactics: discovery

About

Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Various utilities and commands may acquire this information, including <code>whoami</code>. In macOS and Linux, the currently logged in user can be identified with <code>w</code> and <code>who</code>. On macOS the <code>dscl . list /Users | grep -v '_'</code> command can also be used to enumerate user accounts. Environment variables, such as <code>%USERNAME%</code> and <code>$USER</code>, may also be used to access this information. On network devices, Network Device CLI commands such as `show users` and `show ssh` can be used to display users currently logged into the device.

Platforms: Linux, macOS, Network Devices, WindowsMITRE ATT&CK ↗

Used by actors

40 known groups

Software

193 malware/tools implement this

PlugXIxesheBISCUITDerusbiDyreSslMMWinMMSys10Mis-TypeS-TypeEpicAgent.btzBackdoor.OldreaTrojan.KaraganyT9000PrikormkaCrimsonRemsecUnknown LoggerPowerDukeRTMMoonWindRedLeavesWINDSHIELDXAgentOSXKomplexGazerFelismusReaverPOWRUNERDownPaperPupyJPINHAPPYWORKWINERACKPOWERSTATSNanHaiShuKwampirsGravityRATROKRATRATANKBASynAckytyGold DragonKoadicZebrocyMosquitoVERMINRGDoorInvisiMoleQuasarRATKazuarTrickBotFELIXROOTQUADAGENTRogueRobinNDiskMonitorUPPERCUTMirageFoxMore_eggsAgent TeslaRemcosDarkCometMicropsiaOctopusAzorultCardinal RATzwShellCannonNOKKIDenisKONNILinux RabbitEmpireEmotetSpeakUpRevenge RATFlawedAmmyyServHelpernjRATHAWKBALLExaramel for LinuxZxShellBabySharkPoetRATHotCroissantRifdoorOkrumPowerShowerLokibotRising SunSHARPSTATSMetamorfoAria-bodyMechaFlounderGet2SDBbotValakGoopyBonadanCryptoisticLiteDukeWellMessWellMailBloodHoundGrandoreiroLuciferSLOTHFULMEDIABazarSparkEgregorSUNBURSTEVILNUMExplosiveCaterpillar WebShellNBTscanShadowPadSideTwistSombRATSodaMasterChaesGrimAgentBoomBoxObliqueRATTurianSMOKEDHAMQakBotMarkiRATBLUELIGHTDiavolClamblingRCSessionSysUpdateGelsemiumChrommmeDarkWatchmanLitePowerLizarNeoichorSILENTTRINITYDRATzarusFlagproZxxZMilanMacMaSaint BotDnsSystemCreepySnailAmadeyAction RATAuTo StealerSquirrelwafflePyDCryptStrifeWaterSmall SieveSTARWHALEBumblebeeFunnyDreammetaMainMafaldaSVCReadyWoody RATBlackCatKOPILUWAKBADHATCHAsyncRATNGLiteSocGholishRaspberry RobinLunarWebMgBotNightdoorRaccoon StealerCHIMNEYSWEEPCuckoo StealerLatrodectusMangoOilBoosterXLoaderBOOKWORMPUBLOADHavocTONESHELLRedLine StealerInvisibleFerretXORIndex LoaderHexEval LoaderPureCrypterLODEINFOHiddenFaceIronWindLAMEHUGRustyWater

Corpus indicators tagged with this technique

1,092 indicators in the corpus carry T1033.

IndicatorTypeFamilySevSrc
cve-2025-2492cve852
cve-2020-22658cve852
cve-2020-22653cve852
cve-2023-44976cveransomware852
5398b7eaa94f0ee570b1c5642b559047hashransomware802
56d1de3159adbfda20aca593c99901f9hashransomware802
6dfef58ef68fb7965a23da8be3141af9hashransomware802
9e5b1e10ad6904d3f5b48d38470cd57263974640a27d13cf793ef026d3d6b886hash802
1344e6bc51cea35befb4adff7a25899bhashransomware802
2a350525ba72ffc9fe45a05a423833d5hashphishing802
10824d14c814524155f2b529cf5fee43hashransomware802
242038139842ec79ec1044c64eb0804ahashransomware802
0b1870d57221eec6f3bbef648e71a724hashransomware802
e20b35a8c30e076cdd0e1df05ba1ff2e418dbd39a674f084787cc0af2fda9e95sha256phishing801
107b5aa3c4ef30b9b832e0a10b1efb1dcf433158bc6af8d890d66c0c9ed50d21sha256801
44f6101dd8171133f53317bfd752300ehash802
9758e76b601798a30d903bf05052a53df80451e5c156548ce9da828f608b6470sha256801
07cd03e2082bcb0b890cc59ce4c770d1a095ac6f1ae9cf999f5542555c56f841sha256phishing801
3d510977d60a44322f88100b515f06cb5ed83babc64247068d1a489595faa6c5sha256phishing801
e5e43b0830369c39fab45363486da4d21a98c5097ea262c9816997f11c73c1c4hashphishing802
24398b75be2645e6c695e529e62e60deb418143a4bbea13c561d3c361419eb54hash802
cd4a51037bf58733c0cb24b273951dd3fcea45a2aaeb8b30a3c625e183c4c0c7hashphishing802
fab69acd743f4111b749e3268690825c38822e62hash802
038cab0c60c53cf12f048272014024c0hashransomware802
91e523a46f3bb860ac2e5800b7e1ec89d75a2408410b9cd25eebc17c8d7a92bchash802
a7bd8869293212e1671df90d2d41b96d4933eb9408b1111bd830e111a91bb202hashphishing802
670384fafb23140d96f2f8fe04a13fc8cc8e2a6e5e8c973e39b58d103c5fea92sha256phishing801
09d0517a1f69feff8186655ae3b567e0hashransomware802
b90988400cced319d260c4937f334ecc364785ed5c593cd2139965e62ca58173sha256phishing801
221a39856b37e3c682f62427f1e6b965b36a2405764689c914672770a01a1fa9sha256801

Showing the top 30 by severity of 1,092.