FORENSIA

ATT&CK · T1087.002 · sub-technique

Domain Account

Tactics: discovery

About

Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges. Commands such as <code>net user /domain</code> and <code>net group /domain</code> of the Net utility, <code>dscacheutil -q group</code> on macOS, and <code>ldapsearch</code> on Linux can list domain users and groups. PowerShell cmdlets including <code>Get-ADUser</code> and <code>Get-ADGroupMember</code> may enumerate members of Active Directory groups.

Platforms: Linux, macOS, WindowsParent: T1087 Account DiscoveryMITRE ATT&CK ↗

Corpus indicators tagged with this technique

462 indicators in the corpus carry T1087.002.

IndicatorTypeFamilySevSrc
cve-2023-52271cveransomware853
cve-2025-23304cve852
cve-2021-27076cve851
cve-2025-1055cveransomware853
cve-2026-22584cve852
cve-2025-68670cve852
cve-2025-61155cveransomware853
cve-2025-0921cve852
cve-2025-66478cve852
42a99a5effdc1d02f6b622537de881e1hashransomware802
479ae5fd7274439ddfa27bc03298ebfdfc5ff17f6412acccf74d4dbd90d94218sha256phishing801
38353f95fff270f4e3a9d7add8c64666020dd668ce66e15969a736ec48cadc59sha256phishing801
259fd28f9e66159d5a30b86688fec184hashransomware802
b0cfa2089802634ffb8c77962cdb18317a6332d4hashransomware802
edbf152ed9ac79e5d9e0111d1071af48hashransomware802
442af2726e22f512b49f67bcdbf7c0d1e806aa8bhashransomware802
2b2e657ae1bc2fdcdfe5201a8e0e5224hashransomware802
874bcb1c3d050a5b5b333a2198f504fcb27927c2abdd43b07440188a380c52d5sha256phishing801
b0e292346b4ab3f83fadd8abcce7cfc5b9d50ef73ad141e8bc4a4689fee13504hashransomware802
f962e15c6efebb3c29fe399bb168066042b616affddd83f72570c979184ec55chashransomware802
4253dd1a4c0867b0be7732f75b2f630cebfb7fed94270e15fb3b12ae40546d01sha256phishing801
28a9982cf2b4fc53a1545b6ed0d0c1788ca9369a847750f5652ffa0ca7f7b7d3hashransomware802
8bd16897409ae5d5667c345276d2532f493c0f98hashransomware802
6a5f9bd0e4a0c385b98cc7b528be53a95ff9c4ccffa8c1f65448ab792a46186csha256801
64a0ab00d90682b1807c5d7da1a4ae67cde4c5757fc7d995d8f126f0ec8ae983hashransomware802
2758f4d71a2a2dfdefab81737c2d776b2a3dafe5844fdd2157e089a28447ca98sha256phishing801
f1551d3e5d144eef4e70a29dd3dc52fb22459d1fhash802
f0b3e112ce4807a28e2b5d66a840ed7fhashransomware802
43f4ca1c7474c0476a42d937dc4af01c8ccfc20331baa0465ac0f3408f52b2e2hashransomware802
54a6743781fd4ceb720331fce92f16186931192dhashransomware802

Showing the top 30 by severity of 462.