Techniques › T1087 › T1087.001
T1087.001 Local Account
discovery — ESXi, Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
4
analytics
13
Sigma rules tagged attack.t1087.001
1
KEV CVEs mapped here
<p>Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.</p><p>Commands such as <code>net user</code> and <code>net localgroup</code> of the Net utility and <code>id</code> and <code>groups</code> on macOS and Linux can list local users and groups. On Linux, local users can also be enumerated through the use of the <code>/etc/passwd</code> file. On macOS, the <code>dscl . list /Users</code> command can be used to enumerate local accounts. On ESXi servers, the
esxcli system account list command can list local user accounts.</p>KEV CVEs mapped to this technique · CTID Mappings Explorer
| CVE | Vendor / product | Mapping type | State | Added |
|---|---|---|---|---|
| CVE-2023-27532 | Veeam Backup & Replication | secondary impact | Mapped | 2023-08-22 |
Detection strategy · ATT&CK Enterprise v19.2
- DET0303 Local Account Enumeration Across Host Platforms v1.0
AN0846 WindowsAdversary enumeration of local user accounts using Net.exe, WMI, or PowerShell.Tunable:
CommandLinePatternUserContextTimeWindowAN0847 LinuxEnumeration of local users or groups via file access (/etc/passwd) or commands like id, groups.Tunable:AccessedFileExecutionScopeAN0848 macOSEnumeration of macOS local users using dscl, id, dscacheutil, or /etc/passwd access.Tunable:CommandLineInteractiveSessionAN0849 ESXiEnumeration of local ESXi accounts using esxcli or vSphere API from unauthorized sessions.Tunable:CommandPatternSessionType
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1087.001
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-01-02 (modified 2025-12-10) · logsource: product=windows category=process_creation · 02030f2f-6199-49ec-b258-ea71b07e03dc
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: C.J. May
· 2022-08-09 (modified 2026-02-19) · logsource: product=windows category=file_event · 02773bed-83bf-469f-b7ff-e676e7d78bab
Detects default file names outputted by the BloodHound collection tool SharpHound
Author: Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements)
· 2019-01-16 (modified 2022-07-11) · logsource: product=windows category=process_creation · 183e7ea8-ac4b-4c23-9aec-b3dac4e401ac
Detects execution of "Net.EXE".
Author: Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community
· 2019-10-21 (modified 2025-10-20) · logsource: product=windows category=process_creation · 502b42de-4306-40b4-9596-6f590c81f073
Local accounts, System Owner/User discovery using operating systems utilities
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-01-20 (modified 2025-12-10) · logsource: product=windows category=ps_module · 7d0d0329-0ef1-4e84-a9f5-49500f9d7c6c
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer
· 2017-03-05 (modified 2025-12-10) · logsource: product=windows category=ps_script · 89819aa4-bbd6-46bc-88ec-c7f7fe30efa6
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Nasreddine Bencherchali (Nextron Systems)
· 2021-12-18 (modified 2026-06-29) · logsource: product=windows category=process_creation · aae1243f-d8af-40d8-ab20-33fc6d0c55bc
Detects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs
Author: Alejandro Ortuno, oscd.community, CheraghiMilad
· 2020-10-08 (modified 2024-12-10) · logsource: product=linux category=process_creation · b45e3d6f-42c6-47d8-a478-df6bd6cf534c
Detects enumeration of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-10-10 · logsource: product=windows category=process_creation · c8a180d6-47a3-4345-a609-53f9c3d834fc
Detects suspicious reconnaissance command line activity on Windows systems using the PowerShell Get-LocalGroupMember Cmdlet
Author: Austin Clark
· 2019-08-11 (modified 2023-01-04) · logsource: product=cisco service=aaa · cd072b25-a418-4f98-8ebc-5093fb38fe1a
Collect pertinent data from the configuration files
Author: Florian Roth (Nextron Systems), omkar72, @svch0st, Nasreddine Bencherchali (Nextron Systems)
· 2019-01-16 (modified 2023-03-02) · logsource: product=windows category=process_creation · d95de845-b83c-4a9a-8a6a-4fc802ebf6c0
Detects suspicious reconnaissance command line activity on Windows systems using Net.EXE
Check if the user that executed the commands is suspicious (e.g. service accounts, LOCAL_SYSTEM)
Author: Alejandro Ortuno, oscd.community
· 2020-10-08 (modified 2026-07-07) · logsource: product=macos category=process_creation · ddf36b67-e872-4507-ab2e-46bda21b842c
Detects enumeration of local system accounts on MacOS systems.
This can be used by attackers to identify accounts for lateral movement or privilege escalation.
Author: Florian Roth (Nextron Systems)
· 2019-12-20 (modified 2023-02-04) · logsource: product=windows category=process_creation · f376c8a7-a2d0-4ddc-aa0c-16c17236d962
Detects command line parameters used by Bloodhound and Sharphound hack tools
Rules tagged at the parent level (attack.t1087) 16
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-01-02 (modified 2025-12-10) · logsource: product=windows category=process_creation · 02030f2f-6199-49ec-b258-ea71b07e03dc
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Florian Roth (Nextron Systems)
· 2017-05-31 (modified 2022-10-09) · logsource: product=windows service=security · 24549159-ac1b-479c-8175-d42aea947cae
This events that are generated when using the hacktool Ruler by Sensepost
Author: Nasreddine Bencherchali (Nextron Systems)
· 2022-10-18 (modified 2023-02-04) · logsource: product=windows category=process_creation · 38646daa-e78f-4ace-9de0-55547b2d30da
Detects the execution of the PUA/Recon tool Seatbelt via PE information of command line parameters
Author: Florian Roth (Nextron Systems)
· 2022-03-17 (modified 2023-11-09) · logsource: product=windows category=process_creation · 4ebc877f-4612-45cb-b3a5-8e3834db36c9
Detects certain parent child patterns found in cases in which a web shell is used to perform certain credential dumping or exfiltration activities on a compromised system
Author: Sagie Dulce, Dekel Paz
· 2022-01-01 · logsource: product=rpc_firewall category=application · 65f77b1e-8e79-45bf-bb67-5988a8ce45a5
Detects remote RPC calls useb by SharpHound to map remote connections and local group membership.
Author: Andreas Braathen (mnemonic.io)
· 2023-10-27 (modified 2024-01-26) · logsource: product=windows category=process_creation · 698d4431-514f-4c82-af4d-cf573872a9f5
Detects system discovery activity carried out by Pikabot, such as incl. network, user info and domain groups.
The malware Pikabot has been seen to use this technique as part of its C2-botnet registration with a short collection time frame (less than 1 minute).
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-01-20 (modified 2025-12-10) · logsource: product=windows category=ps_module · 7d0d0329-0ef1-4e84-a9f5-49500f9d7c6c
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer
· 2017-03-05 (modified 2025-12-10) · logsource: product=windows category=ps_script · 89819aa4-bbd6-46bc-88ec-c7f7fe30efa6
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Georg Lauenstein (sure[secure])
· 2022-09-19 (modified 2023-03-23) · logsource: product=windows category=process_creation · 98b53e78-ebaf-46f8-be06-421aafd176d9
WinPEAS is a script that search for possible paths to escalate privileges on Windows hosts. The checks are explained on book.hacktricks.xyz
Author: Nasreddine Bencherchali (Nextron Systems)
· 2021-12-18 (modified 2026-06-29) · logsource: product=windows category=process_creation · aae1243f-d8af-40d8-ab20-33fc6d0c55bc
Detects usage of the PsLogList utility to dump event log in order to extract admin accounts and perform account discovery or delete events logs
Author: @kostastsale
· 2024-01-26 · logsource: product=windows category=network_connection · b3ad3c0f-c949-47a1-a30e-b0491ccae876
Detects uncommon network connections to the Active Directory Web Services (ADWS) from processes not typically associated with ADWS management.
Author: Nasreddine Bencherchali (Nextron Systems), X__Junior (Nextron Systems)
· 2022-09-09 (modified 2025-12-02) · logsource: product=windows category=process_creation · beaa66d6-aa1b-4e3c-80f5-e0145369bfaf
Detects execution of different log query utilities and commands to search and dump the content of specific event logs or look for specific event IDs.
This technique is used by threat actors in order to extract sensitive information from events logs such as usernames, IP addresses, hostnames, etc.
Author: Florian Roth (Nextron Systems), Jonhnathan Ribeiro, Anton Kutepov, oscd.community, Chad Hudson, Matt Anderson
· 2017-01-01 (modified 2026-07-14) · logsource: product=windows category=process_creation · bed2a484-9348-4143-8a8a-b801c979301c
Detects certain command line parameters often used during reconnaissance activity via web shells
Author: Florian Roth (Nextron Systems)
· 2022-02-07 · logsource: product=windows category=process_creation · e6313acd-208c-44fc-a0ff-db85d572e90e
Detects a set of suspicious network related commands often used in recon stages
Author: @kostastsale
· 2024-01-26 · logsource: product=windows category=process_creation · e92a4287-e072-4a40-9739-370c106bb750
Detects the execution of SOAPHound, a .NET tool for collecting Active Directory data, using specific command-line arguments that may indicate an attempt to extract sensitive AD information.
Author: Florian Roth (Nextron Systems), MSTI (query)
· 2022-10-01 · logsource: product=windows category=process_creation · fa3c117a-bc0d-416e-a31b-0c0e80653efb
Detects patterns found in process executions cause by China Chopper like tiny (ASPX) webshells