Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0303 — Local Account Enumeration Across Host Platforms
DET0303

Local Account Enumeration Across Host Platforms

4 analytic(s) · 1 technique(s) detected

Analytics

4
AN0846 Analytic 0846
Windows

Adversary enumeration of local user accounts using Net.exe, WMI, or PowerShell.

WinEventLog:Sysmon EventCode=1
[CommandLinePattern] Detects variations of 'net user', 'net localgroup', 'Get-LocalUser'.
[UserContext] Restrict monitoring to low-privileged or unexpected users executing enumeration.
[TimeWindow] Tune for bursts of enumeration commands in short succession.
AN0847 Analytic 0847
Linux

Enumeration of local users or groups via file access (/etc/passwd) or commands like id, groups.

auditd:PATH PATH linux:Sysmon EventCode=1
[AccessedFile] Monitors sensitive file access such as '/etc/passwd', '/etc/group'.
[ExecutionScope] Restrict detection to user-initiated sessions or specific parent processes.
AN0848 Analytic 0848
macOS

Enumeration of macOS local users using dscl, id, dscacheutil, or /etc/passwd access.

macos:unifiedlog None
[CommandLine] Monitor dscl . list /Users, dscacheutil -q user, id -un.
[InteractiveSession] Focus on enumeration from non-console users or untrusted apps.
AN0849 Analytic 0849
ESXi

Enumeration of local ESXi accounts using esxcli or vSphere API from unauthorized sessions.

vpxd.log vCenter Management esxi:shell Shell Execution
[CommandPattern] Look for 'esxcli system account list' and API calls from unusual sources.
[SessionType] Restrict detection to interactive sessions vs. maintenance/automation jobs.

Detected Techniques

1

Details

MITRE ID
DET0303
STIX ID
x-mitre-detection-strategy--21ad7ddc-77f6-422b-8e0c-c82e184e0ad0
Analytics
4
Techniques Detected
1
By Tactic
Discovery
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.