FORENSIA

ATT&CK · T1069

Permission Groups Discovery

Tactics: discovery

About

Adversaries may attempt to discover group and permission settings. This information can help adversaries determine which user accounts and groups are available, the membership of users in particular groups, and which users and groups have elevated permissions. Adversaries may attempt to discover group permission settings in many different ways. This data may provide the adversary with information about the compromised environment that can be used in follow-on activity and targeting.

Platforms: Containers, IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, WindowsMITRE ATT&CK ↗

Used by actors

6 known groups

Software

6 malware/tools implement this

MURKYTOPTrickBotCarbonShimRatReporterIcedIDSiloscape

Corpus indicators tagged with this technique

65 indicators in the corpus carry T1069.

IndicatorTypeFamilySevSrc
738d4398e7d11427051093ba8a6f37e51470795chash802
34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bcsha256ransomware801
8c935feec4bd05d5d918df308be417532fb42608fb989a08eab183e0ae699235sha256ransomware801
7b6e094d98eb3f695e5856db4d8d22e11898cec9hash802
59e3c4cb06331b4f2d78a9a0592f3747e573bd01c5a7650c26361d1e25520712sha256ransomware801
4c71357de3c0b12094693ca6eff94cadhash802
f591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344esha256ransomware801
3ddd90b99ee7ac3ec39e1d22b67c257d273a0970hash802
3d00e34594dbaba266f301ca37246e06hash802
a1c3520282c81afabdefa4834b96563edf95c3c7hash802
99911fce9e0d697c99421b81e8fe2a04hash802
f694401d8e80bb0f672b1b30fd7b153ahash802
efc71bd23572eec985a6d1bbf61308fdhash802
c46bac27b5ca151afabd22c5546f78ae2ae3a20dhash802
f1551d3e5d144eef4e70a29dd3dc52fb22459d1fhash802
db972979d508e75fe730d3b72c2701470fbdaeaf8ebdd674744754fa44438ca5sha256ransomware801
ebcf977806f68af3147e0b78b55f6aedhash802
cc19e502e4201cc974c753b96429027925224f53hash802
3f797a639bc855bc6d5471f327924b62d10900ddec49b970eca6604142bbb4besha256ransomware801
111e8abb4b8592172d597926f47f018chash802
131877a052f62750d815cf55d4c14f606a26025e3094e1b8bb18bd1668e3beaahashransomware801
48d4872e8463d1ede1b93e3f6a6a8cc8c2cecde3sha1ransomware781
dc96668d007df0a545bf1334e10e80famd5ransomware761
http://www.drivelivelime.com/xurl752
http://www.drivelivelime.com/pwurl752
http://trafficmanagerupdate.com/index.phpurl752
http://msiidentity.com/pwurl752
http://azurenetfiles.net:443/agent.ashxurl752
http://thomphon.com/update.msiurlransomware751
144.31.53.78ipransomware701

Showing the top 30 by severity of 65.