{"id":"T1589.002","name":"Email Addresses","url":"https://attack.mitre.org/techniques/T1589/002","tactics":["reconnaissance"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0814","stix_id":"x-mitre-detection-strategy--33040f26-43e3-4c1d-8557-02f306bb028f","name":"Detection of Email Addresses","url":"https://attack.mitre.org/detectionstrategies/DET0814","analytics":[{"id":"AN1946","stix_id":"x-mitre-analytic--b123fe68-1da5-4c80-b4f0-f3d476891e11","name":"Analytic 1946","description":"Monitor for suspicious network traffic that could be indicative of probing for email addresses and/or usernames, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.","url":"https://attack.mitre.org/detectionstrategies/DET0814#AN1946","platforms":["PRE"],"log_source_references":[{"name":"Network Traffic","channel":"None","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"network-traffic"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0814"],"techniques":["T1589.002"]}],"live":true,"version":"1.0","techniques":["T1589.002"]}],"sigma_rules":[{"id":"cdfa73b6-3c9d-4bb8-97f8-ddbd8921f5c5","title":"Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock","author":"frack113","status":"experimental","level":"medium","date":"2025-03-05","modified":null,"description":"Detects the use of the \"Get-ADComputer\" cmdlet in order to identify systems which are configured for unconstrained delegation.","references":["https://pentestlab.blog/2022/03/21/unconstrained-delegation/","https://learn.microsoft.com/en-us/powershell/module/activedirectory/get-adcomputer?view=windowsserver2022-ps"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.reconnaissance","attack.discovery","attack.credential-access","attack.t1018","attack.t1558","attack.t1589.002"],"path":"rules/windows/powershell/powershell_script/posh_ps_potential_unconstrained_delegation_discovery.yml","techniques":["T1018","T1558","T1589.002"],"cves":[]}],"kev_cves":[],"_built":"2026-08-24 19:45 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}