ATT&CK · T1069.002 · sub-technique
Domain Groups
Tactics: discovery
About
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators. Commands such as <code>net group /domain</code> of the Net utility, <code>dscacheutil -q group</code> on macOS, and <code>ldapsearch</code> on Linux can list domain-level groups.
Used by actors
13 known groups
Software
23 malware/tools implement this
Corpus indicators tagged with this technique
56 indicators in the corpus carry T1069.002.
Showing the top 30 by severity of 56.