FORENSIA

ATT&CK · T1087

Account Discovery

Tactics: discovery

About

Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts exist, which can aid in follow-on behavior such as brute-forcing, spear-phishing attacks, or account takeovers (e.g., Valid Accounts). Adversaries may use several methods to enumerate accounts, including abuse of existing tools, built-in commands, and potential misconfigurations that leak account names and roles or permissions in the targeted environment. For examples, cloud environments typically provide easily accessible interfaces to obtain user lists. On hosts, adversaries can use default PowerShell and other command line functionality to identify accounts. Information about email addresses and accounts may also be extracted by searching an infected system’s files.

Platforms: ESXi, IaaS, Identity Provider, Linux, macOS, Office Suite, SaaS, WindowsMITRE ATT&CK ↗

Used by actors

3 known groups

Software

5 malware/tools implement this

ShimRatReporterXCSSETWoody RATHavocTONESHELL

Corpus indicators tagged with this technique

263 indicators in the corpus carry T1087.

IndicatorTypeFamilySevSrc
cve-2022-47945cve851
cve-2013-3307cve852
cve-2016-5681cve852
cve-2025-11837cve852
0ffb4b4e430f4b69216fb9d2e082e482hash802
44f6101dd8171133f53317bfd752300ehash802
6f761f63642cd6329a29cfad80be50c3hash802
59e3c4cb06331b4f2d78a9a0592f3747e573bd01c5a7650c26361d1e25520712sha256ransomware801
dce5df29bddff5a4ddaea5c4fec14da91f7b69063a6e1c45ed61e5da4fc6c87bsha256802
3f797a639bc855bc6d5471f327924b62d10900ddec49b970eca6604142bbb4besha256ransomware801
db972979d508e75fe730d3b72c2701470fbdaeaf8ebdd674744754fa44438ca5sha256ransomware801
8c935feec4bd05d5d918df308be417532fb42608fb989a08eab183e0ae699235sha256ransomware801
fab69acd743f4111b749e3268690825c38822e62hash802
f591275a8f014b29e567529d67c54eb7bb4473db1c38737d6bfd5b3d52c9344esha256ransomware801
78a82d93b4f580835f5823b85a3d9ee1f03a15ee6f0e01b4eac86252a7002981hashsupply_chain801
99813f3d0625e880158c68039c0e2fbf488db0be3db77cd1ce6d382644193f0ehash802
9e5b1e10ad6904d3f5b48d38470cd57263974640a27d13cf793ef026d3d6b886hash802
19232d0eff3ef7aee3b5d7620c72358chash802
7b361a6d0d42309d09ec9000b53712b3hash802
8cc249b16adf7e4a658af7fa31d7998ehash802
308351124c496d4f4effee65ab828506abf70385773c167ab1f32a7f030385achash802
3b6cb20891bce8602ce669187754871e402a1782031ef8b032cd007e3894bc5dhash802
6a69ea2ce3fea0ebfd7a32a1dfc4251bd4d7d8a4fbd44aaa47b82290d0414a9fhash802
6c700ca4e6d917c7aa9d964e98604a0349d9b8b4673df96a3f73a3d2d042635ahash802
d78f64551d1b31a31e5998e442f0debd458e011e05019b3951d9ddde997f8384hash802
34d798a6c55e57ed0932b6499f4fbcb5454bdfca903307be101a0594b0ac07bcsha256ransomware801
36ff9f683e870145aaf5a715bc934762hash802
6869f24aecd75e2144aba8dc03dc2d0fhash802
91e523a46f3bb860ac2e5800b7e1ec89d75a2408410b9cd25eebc17c8d7a92bchash802
6f91d1f8f0cbaab137351936b52f7a94hash802

Showing the top 30 by severity of 263.