{"id":"T1069.001","name":"Local Groups","url":"https://attack.mitre.org/techniques/T1069/001","tactics":["discovery"],"platforms":["Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0114","stix_id":"x-mitre-detection-strategy--de120f6a-c19b-4346-b62f-c8cd95fcb291","name":"Behavioral Detection of Local Group Enumeration Across OS Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0114","analytics":[{"id":"AN0317","stix_id":"x-mitre-analytic--78f4f0fe-55ef-4598-85ac-865cba1920d3","name":"Analytic 0317","description":"Detects attempts to enumerate local groups via Net.exe, PowerShell, or native API calls that precede lateral movement or privilege abuse.","url":"https://attack.mitre.org/detectionstrategies/DET0114#AN0317","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4688","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-security"}],"mutable_elements":[{"field":"TimeWindow","description":"Time window between group enumeration and lateral movement or privilege escalation activity."},{"field":"UserContext","description":"Whether the process was executed by a privileged or low-privilege account."}],"live":true,"detection_strategies":["DET0114"],"techniques":["T1069.001"]},{"id":"AN0318","stix_id":"x-mitre-analytic--a62a2b36-00e9-481c-9a3a-14c14cd42dae","name":"Analytic 0318","description":"Detects enumeration of local groups using common binaries (groups, getent, cat /etc/group) or scripting with suspicious lineage.","url":"https://attack.mitre.org/detectionstrategies/DET0114#AN0318","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"ProcessName","description":"Detection tuning for binaries like `groups`, `getent`, `awk`, or `cut` that may be used in pipelines."},{"field":"ParentProcess","description":"Used to determine whether enumeration was triggered by a script or terminal."}],"live":true,"detection_strategies":["DET0114"],"techniques":["T1069.001"]},{"id":"AN0319","stix_id":"x-mitre-analytic--66923fbc-1d4d-4945-89dd-102a8e2c6122","name":"Analytic 0319","description":"Detects use of dscl or id/group commands to enumerate local system groups, often by post-exploitation tools or persistence checks.","url":"https://attack.mitre.org/detectionstrategies/DET0114#AN0319","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"process:exec","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"CommandLineContains","description":"Match on specific dscl paths like '/Groups' or known enumeration options."},{"field":"InteractiveSession","description":"Used to scope out enumeration from user terminals versus background utilities."}],"live":true,"detection_strategies":["DET0114"],"techniques":["T1069.001"]}],"live":true,"version":"1.0","techniques":["T1069.001"]}],"sigma_rules":[{"id":"02030f2f-6199-49ec-b258-ea71b07e03dc","title":"Malicious PowerShell Commandlets - ProcessCreation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-02","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/process_creation/proc_creation_win_powershell_malicious_cmdlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"02773bed-83bf-469f-b7ff-e676e7d78bab","title":"BloodHound Collection Files","author":"C.J. May","status":"test","level":"high","date":"2022-08-09","modified":"2026-02-19","description":"Detects default file names outputted by the BloodHound collection tool SharpHound","references":["https://academy.hackthebox.com/course/preview/active-directory-bloodhound/bloodhound--data-collection"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.discovery","attack.t1087.001","attack.t1087.002","attack.t1482","attack.t1069.001","attack.t1069.002","attack.execution","attack.t1059.001"],"path":"rules/windows/file/file_event/file_event_win_bloodhound_collection.yml","techniques":["T1087.001","T1087.002","T1482","T1069.001","T1069.002","T1059.001"],"cves":[]},{"id":"164eda96-11b2-430b-85ff-6a265c15bf32","title":"Local Groups Reconnaissance Via Wmic.EXE","author":"frack113","status":"test","level":"low","date":"2021-12-12","modified":"2023-02-14","description":"Detects the execution of \"wmic\" with the \"group\" flag.\nAdversaries may attempt to find local system groups and permission settings.\nThe knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group.\nAdversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1069.001"],"path":"rules/windows/process_creation/proc_creation_win_wmic_recon_group.yml","techniques":["T1069.001"],"cves":[]},{"id":"183e7ea8-ac4b-4c23-9aec-b3dac4e401ac","title":"Net.EXE Execution","author":"Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements)","status":"test","level":"low","date":"2019-01-16","modified":"2022-07-11","description":"Detects execution of \"Net.EXE\".","references":["https://pentest.blog/windows-privilege-escalation-methods-for-pentesters/","https://eqllib.readthedocs.io/en/latest/analytics/4d2e7fc1-af0b-4915-89aa-03d25ba7805e.html","https://eqllib.readthedocs.io/en/latest/analytics/e61f557c-a9d0-4c25-ab5b-bbc46bb24deb.html","https://eqllib.readthedocs.io/en/latest/analytics/9b3dd402-891c-4c4d-a662-28947168ce61.html","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1007/T1007.md#atomic-test-2---system-service-discovery---netexe"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1007","attack.t1049","attack.t1018","attack.t1135","attack.t1201","attack.t1069.001","attack.t1069.002","attack.t1087.001","attack.t1087.002","attack.lateral-movement","attack.t1021.002","attack.s0039","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_net_execution.yml","techniques":["T1007","T1049","T1018","T1135","T1201","T1069.001","T1069.002","T1087.001","T1087.002","T1021.002"],"cves":[]},{"id":"676381a6-15ca-4d73-a9c8-6a22e970b90d","title":"Local Groups Discovery - Linux","author":"Ömer Günal, Alejandro Ortuno, oscd.community","status":"test","level":"low","date":"2020-10-11","modified":"2025-06-04","description":"Detects enumeration of local system groups. Adversaries may attempt to find local system groups and permission settings","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.discovery","attack.t1069.001"],"path":"rules/linux/process_creation/proc_creation_lnx_local_groups.yml","techniques":["T1069.001"],"cves":[]},{"id":"6942bd25-5970-40ab-af49-944247103358","title":"Suspicious Get Information for SMB Share - PowerShell Module","author":"frack113","status":"test","level":"low","date":"2021-12-15","modified":"2022-12-02","description":"Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and\nto identify potential systems of interest for Lateral Movement.\nNetworks often contain shared network drives and folders that enable users to access file directories on various systems across a network.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.002/T1069.002.md"],"logsource":{"product":"windows","category":"ps_module"},"tags":["attack.discovery","attack.t1069.001"],"path":"rules/windows/powershell/powershell_module/posh_pm_susp_smb_share_reco.yml","techniques":["T1069.001"],"cves":[]},{"id":"7d0d0329-0ef1-4e84-a9f5-49500f9d7c6c","title":"Malicious PowerShell Commandlets - PoshModule","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-20","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"ps_module"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/powershell/powershell_module/posh_pm_malicious_commandlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"815bfc17-7fc6-4908-a55e-2f37b98cedb4","title":"AD Groups Or Users Enumeration Using PowerShell - PoshModule","author":"frack113","status":"test","level":"low","date":"2021-12-15","modified":"2023-01-20","description":"Adversaries may attempt to find domain-level groups and permission settings.\nThe knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group.\nAdversaries may use this information to determine which users have elevated permissions, such as domain administrators.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.002/T1069.002.md"],"logsource":{"product":"windows","category":"ps_module"},"tags":["attack.discovery","attack.t1069.001"],"path":"rules/windows/powershell/powershell_module/posh_pm_susp_ad_group_reco.yml","techniques":["T1069.001"],"cves":[]},{"id":"88f0884b-331d-403d-a3a1-b668cf035603","title":"AD Groups Or Users Enumeration Using PowerShell - ScriptBlock","author":"frack113","status":"test","level":"low","date":"2021-12-15","modified":"2022-12-25","description":"Adversaries may attempt to find domain-level groups and permission settings.\nThe knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group.\nAdversaries may use this information to determine which users have elevated permissions, such as domain administrators.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.002/T1069.002.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.discovery","attack.t1069.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_ad_group_reco.yml","techniques":["T1069.001"],"cves":[]},{"id":"89819aa4-bbd6-46bc-88ec-c7f7fe30efa6","title":"Malicious PowerShell Commandlets - ScriptBlock","author":"Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer","status":"test","level":"high","date":"2017-03-05","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_malicious_commandlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"89bb1f97-c7b9-40e8-b52b-7d6afbd67276","title":"Local Groups Discovery - MacOs","author":"Ömer Günal, Alejandro Ortuno, oscd.community","status":"test","level":"informational","date":"2020-10-11","modified":"2022-11-27","description":"Detects enumeration of local system groups","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.discovery","attack.t1069.001"],"path":"rules/macos/process_creation/proc_creation_macos_local_groups.yml","techniques":["T1069.001"],"cves":[]},{"id":"95f0643a-ed40-467c-806b-aac9542ec5ab","title":"Suspicious Get Information for SMB Share","author":"frack113","status":"test","level":"low","date":"2021-12-15","modified":"2022-12-25","description":"Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as\na precursor for Collection and to identify potential systems of interest for Lateral Movement.\nNetworks often contain shared network drives and folders that enable users to access file directories on various systems across a network.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.002/T1069.002.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.discovery","attack.t1069.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_smb_share_reco.yml","techniques":["T1069.001"],"cves":[]},{"id":"c625d754-6a3d-4f65-9c9a-536aea960d37","title":"Permission Check Via Accesschk.EXE","author":"Teymur Kheirkhabarov (idea), Mangatas Tondang, oscd.community, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2020-10-13","modified":"2026-06-29","description":"Detects the usage of the \"Accesschk\" utility, an access and privilege audit tool developed by SysInternal and often being abused by attacker to verify process privileges","references":["https://speakerdeck.com/heirhabarov/hunting-for-privilege-escalation-in-windows-environment?slide=43","https://www.youtube.com/watch?v=JGs-aKf2OtU&ab_channel=OFFZONEMOSCOW","https://github.com/carlospolop/PEASS-ng/blob/fa0f2e17fbc1d86f1fd66338a40e665e7182501d/winPEAS/winPEASbat/winPEAS.bat","https://github.com/gladiatx0r/Powerless/blob/04f553bbc0c65baf4e57344deff84e3f016e6b51/Powerless.bat"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1069.001"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_accesschk_check_permissions.yml","techniques":["T1069.001"],"cves":[]},{"id":"cef24b90-dddc-4ae1-a09a-8764872f69fc","title":"Suspicious Get Local Groups Information","author":"frack113","status":"test","level":"low","date":"2021-12-12","modified":"2025-08-22","description":"Detects the use of PowerShell modules and cmdlets to gather local group information.\nAdversaries may use local system permission groups to determine which groups exist and which users belong to a particular group such as the local administrators group.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md"],"logsource":{"product":"windows","category":"ps_module"},"tags":["attack.discovery","attack.t1069.001"],"path":"rules/windows/powershell/powershell_module/posh_pm_susp_local_group_reco.yml","techniques":["T1069.001"],"cves":[]},{"id":"f376c8a7-a2d0-4ddc-aa0c-16c17236d962","title":"HackTool - Bloodhound/Sharphound Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-12-20","modified":"2023-02-04","description":"Detects command line parameters used by Bloodhound and Sharphound hack tools","references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/BloodHoundAD/SharpHound"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1087.001","attack.t1087.002","attack.t1482","attack.t1069.001","attack.t1069.002","attack.execution","attack.t1059.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_bloodhound_sharphound.yml","techniques":["T1087.001","T1087.002","T1482","T1069.001","T1069.002","T1059.001"],"cves":[]},{"id":"fa6a5a45-3ee2-4529-aa14-ee5edc9e29cb","title":"Suspicious Get Local Groups Information - PowerShell","author":"frack113","status":"test","level":"low","date":"2021-12-12","modified":"2025-08-22","description":"Detects the use of PowerShell modules and cmdlets to gather local group information.\nAdversaries may use local system permission groups to determine which groups exist and which users belong to a particular group such as the local administrators group.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1069.001/T1069.001.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.discovery","attack.t1069.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_susp_local_group_reco.yml","techniques":["T1069.001"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}