Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Attack Patterns T1069 — Permission Groups Discovery
T1069

Permission Groups Discovery

Discovery
TLP:CLEAR

Description

Adversaries may attempt to discover group and permission settings. This information can help adversaries determine which user accounts and groups are available, the membership of users in particular groups, and which users and groups have elevated permissions. Adversaries may attempt to discover group permission settings in many different ways. This data may provide the adversary with information about the compromised environment that can be used in follow-on activity and targeting.(Citation: CrowdStrike BloodHound April 2018)

MITRE ATT&CK Detection Strategies
1

DET0179 Behavioral Detection of Permission Groups Discovery
AN0508 Linux

Detection of group enumeration using commands like 'id', 'groups', or 'getent group', often followed by privilege escalation or SSH lateral movement.

auditd:SYSCALL
AN0509 macOS

Group membership checks via 'dscl', 'dscacheutil', or 'id', typically executed via terminal or automation scripts.

macos:unifiedlog
AN0507 Windows

Detection of adversary enumeration of domain or local group memberships via native tools such as net.exe, PowerShell, or WMI. This activity may precede lateral movement or privilege escalation.

WinEventLog:Security WinEventLog:PowerShell

Details

Platforms
Containers
Iaas
Identity provider
Linux
Macos
Office suite
Saas
Windows
Added
May 2, 2026
Leaving Threaticon

This link opens an external site that isn't part of the platform.