{"id":"T1087.001","name":"Local Account","url":"https://attack.mitre.org/techniques/T1087/001","tactics":["discovery"],"platforms":["ESXi","Linux","macOS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0303","stix_id":"x-mitre-detection-strategy--21ad7ddc-77f6-422b-8e0c-c82e184e0ad0","name":"Local Account Enumeration Across Host Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0303","analytics":[{"id":"AN0846","stix_id":"x-mitre-analytic--6ffbdad6-3d60-452b-9e04-a8292d0125e9","name":"Analytic 0846","description":"Adversary enumeration of local user accounts using Net.exe, WMI, or PowerShell.","url":"https://attack.mitre.org/detectionstrategies/DET0303#AN0846","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"CommandLinePattern","description":"Detects variations of 'net user', 'net localgroup', 'Get-LocalUser'."},{"field":"UserContext","description":"Restrict monitoring to low-privileged or unexpected users executing enumeration."},{"field":"TimeWindow","description":"Tune for bursts of enumeration commands in short succession."}],"live":true,"detection_strategies":["DET0303"],"techniques":["T1087.001"]},{"id":"AN0847","stix_id":"x-mitre-analytic--7b87b63c-0936-48b5-8017-47bf5561e6f9","name":"Analytic 0847","description":"Enumeration of local users or groups via file access (/etc/passwd) or commands like id, groups.","url":"https://attack.mitre.org/detectionstrategies/DET0303#AN0847","platforms":["Linux"],"log_source_references":[{"name":"auditd:PATH","channel":"PATH","data_component":"DC0055","data_component_name":"File Access","log_source_slug":"auditd-path"},{"name":"linux:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"linux-sysmon"}],"mutable_elements":[{"field":"AccessedFile","description":"Monitors sensitive file access such as '/etc/passwd', '/etc/group'."},{"field":"ExecutionScope","description":"Restrict detection to user-initiated sessions or specific parent processes."}],"live":true,"detection_strategies":["DET0303"],"techniques":["T1087.001"]},{"id":"AN0848","stix_id":"x-mitre-analytic--be680af0-8d5f-482c-9042-f5d4921e65f8","name":"Analytic 0848","description":"Enumeration of macOS local users using dscl, id, dscacheutil, or /etc/passwd access.","url":"https://attack.mitre.org/detectionstrategies/DET0303#AN0848","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"None","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"CommandLine","description":"Monitor dscl . list /Users, dscacheutil -q user, id -un."},{"field":"InteractiveSession","description":"Focus on enumeration from non-console users or untrusted apps."}],"live":true,"detection_strategies":["DET0303"],"techniques":["T1087.001"]},{"id":"AN0849","stix_id":"x-mitre-analytic--d2bca034-2f97-4c64-ac30-e75d24886be7","name":"Analytic 0849","description":"Enumeration of local ESXi accounts using esxcli or vSphere API from unauthorized sessions.","url":"https://attack.mitre.org/detectionstrategies/DET0303#AN0849","platforms":["ESXi"],"log_source_references":[{"name":"vpxd.log","channel":"vCenter Management","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"vpxd-log"},{"name":"esxi:shell","channel":"Shell Execution","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"esxi-shell"}],"mutable_elements":[{"field":"CommandPattern","description":"Look for 'esxcli system account list' and API calls from unusual sources."},{"field":"SessionType","description":"Restrict detection to interactive sessions vs. maintenance/automation jobs."}],"live":true,"detection_strategies":["DET0303"],"techniques":["T1087.001"]}],"live":true,"version":"1.0","techniques":["T1087.001"]}],"sigma_rules":[{"id":"02030f2f-6199-49ec-b258-ea71b07e03dc","title":"Malicious PowerShell Commandlets - ProcessCreation","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-02","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/process_creation/proc_creation_win_powershell_malicious_cmdlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"02773bed-83bf-469f-b7ff-e676e7d78bab","title":"BloodHound Collection Files","author":"C.J. May","status":"test","level":"high","date":"2022-08-09","modified":"2026-02-19","description":"Detects default file names outputted by the BloodHound collection tool SharpHound","references":["https://academy.hackthebox.com/course/preview/active-directory-bloodhound/bloodhound--data-collection"],"logsource":{"product":"windows","category":"file_event"},"tags":["attack.discovery","attack.t1087.001","attack.t1087.002","attack.t1482","attack.t1069.001","attack.t1069.002","attack.execution","attack.t1059.001"],"path":"rules/windows/file/file_event/file_event_win_bloodhound_collection.yml","techniques":["T1087.001","T1087.002","T1482","T1069.001","T1069.002","T1059.001"],"cves":[]},{"id":"183e7ea8-ac4b-4c23-9aec-b3dac4e401ac","title":"Net.EXE Execution","author":"Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements)","status":"test","level":"low","date":"2019-01-16","modified":"2022-07-11","description":"Detects execution of \"Net.EXE\".","references":["https://pentest.blog/windows-privilege-escalation-methods-for-pentesters/","https://eqllib.readthedocs.io/en/latest/analytics/4d2e7fc1-af0b-4915-89aa-03d25ba7805e.html","https://eqllib.readthedocs.io/en/latest/analytics/e61f557c-a9d0-4c25-ab5b-bbc46bb24deb.html","https://eqllib.readthedocs.io/en/latest/analytics/9b3dd402-891c-4c4d-a662-28947168ce61.html","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1007/T1007.md#atomic-test-2---system-service-discovery---netexe"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1007","attack.t1049","attack.t1018","attack.t1135","attack.t1201","attack.t1069.001","attack.t1069.002","attack.t1087.001","attack.t1087.002","attack.lateral-movement","attack.t1021.002","attack.s0039","detection.threat-hunting"],"path":"rules-threat-hunting/windows/process_creation/proc_creation_win_net_execution.yml","techniques":["T1007","T1049","T1018","T1135","T1201","T1069.001","T1069.002","T1087.001","T1087.002","T1021.002"],"cves":[]},{"id":"502b42de-4306-40b4-9596-6f590c81f073","title":"Local Accounts Discovery","author":"Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community","status":"test","level":"low","date":"2019-10-21","modified":"2025-10-20","description":"Local accounts, System Owner/User discovery using operating systems utilities","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1033/T1033.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1033","attack.t1087.001"],"path":"rules/windows/process_creation/proc_creation_win_susp_local_system_owner_account_discovery.yml","techniques":["T1033","T1087.001"],"cves":[]},{"id":"7d0d0329-0ef1-4e84-a9f5-49500f9d7c6c","title":"Malicious PowerShell Commandlets - PoshModule","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2023-01-20","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/sadshade/veeam-creds/blob/6010eaf31ba41011b58d6af3950cffbf6f5cea32/Veeam-Get-Creds.ps1","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"ps_module"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/powershell/powershell_module/posh_pm_malicious_commandlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"89819aa4-bbd6-46bc-88ec-c7f7fe30efa6","title":"Malicious PowerShell Commandlets - ScriptBlock","author":"Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer","status":"test","level":"high","date":"2017-03-05","modified":"2025-12-10","description":"Detects Commandlet names from well-known PowerShell exploitation frameworks","references":["https://adsecurity.org/?p=2921","https://github.com/S3cur3Th1sSh1t/PowerSharpPack/tree/master/PowerSharpBinaries","https://github.com/BC-SECURITY/Invoke-ZeroLogon/blob/111d17c7fec486d9bb23387e2e828b09a26075e4/Invoke-ZeroLogon.ps1","https://github.com/xorrior/RandomPS-Scripts/blob/848c919bfce4e2d67b626cbcf4404341cfe3d3b6/Get-DXWebcamVideo.ps1","https://github.com/rvrsh3ll/Misc-Powershell-Scripts/blob/6f23bb41f9675d7e2d32bacccff75e931ae00554/OfficeMemScraper.ps1","https://github.com/dafthack/DomainPasswordSpray/blob/b13d64a5834694aa73fd2aea9911a83027c465a7/DomainPasswordSpray.ps1","https://unit42.paloaltonetworks.com/threat-assessment-black-basta-ransomware/","https://research.nccgroup.com/2022/06/06/shining-the-light-on-black-basta/","https://github.com/calebstewart/CVE-2021-1675","https://github.com/BloodHoundAD/BloodHound/blob/0927441f67161cc6dc08a53c63ceb8e333f55874/Collectors/AzureHound.ps1","https://bloodhound.readthedocs.io/en/latest/data-collection/azurehound.html","https://github.com/HarmJ0y/DAMP","https://github.com/samratashok/nishang","https://github.com/DarkCoderSc/PowerRunAsSystem/","https://github.com/besimorhino/powercat","https://github.com/Kevin-Robertson/Powermad","https://github.com/adrecon/ADRecon","https://github.com/adrecon/AzureADRecon","https://github.com/The-Viper-One/Invoke-PowerDPAPI/","https://github.com/Arno0x/DNSExfiltrator/"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.execution","attack.discovery","attack.t1482","attack.t1087","attack.t1087.001","attack.t1087.002","attack.t1069.001","attack.t1069.002","attack.t1069","attack.t1059.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_malicious_commandlets.yml","techniques":["T1482","T1087","T1087.001","T1087.002","T1069.001","T1069.002","T1069","T1059.001"],"cves":[]},{"id":"aae1243f-d8af-40d8-ab20-33fc6d0c55bc","title":"Suspicious Use of PsLogList","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2021-12-18","modified":"2026-06-29","description":"Detects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs","references":["https://research.nccgroup.com/2021/01/12/abusing-cloud-services-to-fly-under-the-radar/","https://www.cybereason.com/blog/deadringer-exposing-chinese-threat-actors-targeting-major-telcos","https://github.com/3CORESec/MAL-CL/tree/master/Descriptors/Sysinternals/PsLogList","https://twitter.com/EricaZelic/status/1614075109827874817"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1087","attack.t1087.001","attack.t1087.002"],"path":"rules/windows/process_creation/proc_creation_win_sysinternals_psloglist.yml","techniques":["T1087","T1087.001","T1087.002"],"cves":[]},{"id":"b45e3d6f-42c6-47d8-a478-df6bd6cf534c","title":"Local System Accounts Discovery - Linux","author":"Alejandro Ortuno, oscd.community, CheraghiMilad","status":"test","level":"low","date":"2020-10-08","modified":"2024-12-10","description":"Detects enumeration of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1087.001/T1087.001.md","https://my.f5.com/manage/s/article/K589","https://man.freebsd.org/cgi/man.cgi?pwd_mkdb"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.discovery","attack.t1087.001"],"path":"rules/linux/process_creation/proc_creation_lnx_local_account.yml","techniques":["T1087.001"],"cves":[]},{"id":"c8a180d6-47a3-4345-a609-53f9c3d834fc","title":"Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2022-10-10","modified":null,"description":"Detects suspicious reconnaissance command line activity on Windows systems using the PowerShell Get-LocalGroupMember Cmdlet","references":["https://www.absolomb.com/2018-01-26-Windows-Privilege-Escalation-Guide/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1087.001"],"path":"rules/windows/process_creation/proc_creation_win_powershell_get_localgroup_member_recon.yml","techniques":["T1087.001"],"cves":[]},{"id":"cd072b25-a418-4f98-8ebc-5093fb38fe1a","title":"Cisco Collect Data","author":"Austin Clark","status":"test","level":"low","date":"2019-08-11","modified":"2023-01-04","description":"Collect pertinent data from the configuration files","references":["https://blog.router-switch.com/2013/11/show-running-config/","https://www.cisco.com/E-Learning/bulk/public/tac/cim/cib/using_cisco_ios_software/cmdrefs/show_startup-config.htm","https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/config-mgmt/configuration/15-sy/config-mgmt-15-sy-book/cm-config-diff.html"],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.discovery","attack.credential-access","attack.collection","attack.t1087.001","attack.t1552.001","attack.t1005"],"path":"rules/network/cisco/aaa/cisco_cli_collect_data.yml","techniques":["T1087.001","T1552.001","T1005"],"cves":[]},{"id":"d95de845-b83c-4a9a-8a6a-4fc802ebf6c0","title":"Suspicious Group And Account Reconnaissance Activity Using Net.EXE","author":"Florian Roth (Nextron Systems), omkar72, @svch0st, Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"medium","date":"2019-01-16","modified":"2023-03-02","description":"Detects suspicious reconnaissance command line activity on Windows systems using Net.EXE\nCheck if the user that executed the commands is suspicious (e.g. service accounts, LOCAL_SYSTEM)\n","references":["https://redcanary.com/blog/how-one-hospital-thwarted-a-ryuk-ransomware-outbreak/","https://thedfirreport.com/2020/10/18/ryuk-in-5-hours/","https://research.nccgroup.com/2022/08/19/back-in-black-unlocking-a-lockbit-3-0-ransomware-attack/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1087.001","attack.t1087.002"],"path":"rules/windows/process_creation/proc_creation_win_net_groups_and_accounts_recon.yml","techniques":["T1087.001","T1087.002"],"cves":[]},{"id":"ddf36b67-e872-4507-ab2e-46bda21b842c","title":"Local System Accounts Discovery - MacOs","author":"Alejandro Ortuno, oscd.community","status":"test","level":"low","date":"2020-10-08","modified":"2026-07-07","description":"Detects enumeration of local system accounts on MacOS systems.\nThis can be used by attackers to identify accounts for lateral movement or privilege escalation.\n","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1087.001/T1087.001.md","https://ss64.com/osx/dscl.html","https://ss64.com/mac/dscacheutil.html"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.discovery","attack.t1087.001"],"path":"rules/macos/process_creation/proc_creation_macos_local_account.yml","techniques":["T1087.001"],"cves":[]},{"id":"f376c8a7-a2d0-4ddc-aa0c-16c17236d962","title":"HackTool - Bloodhound/Sharphound Execution","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2019-12-20","modified":"2023-02-04","description":"Detects command line parameters used by Bloodhound and Sharphound hack tools","references":["https://github.com/BloodHoundAD/BloodHound","https://github.com/BloodHoundAD/SharpHound"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.discovery","attack.t1087.001","attack.t1087.002","attack.t1482","attack.t1069.001","attack.t1069.002","attack.execution","attack.t1059.001"],"path":"rules/windows/process_creation/proc_creation_win_hktl_bloodhound_sharphound.yml","techniques":["T1087.001","T1087.002","T1482","T1069.001","T1069.002","T1059.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-27532","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}