T1033 System Owner/User Discovery — ATT&CK Technique
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Various utilities and commands may acquire this information, including whoami. In macOS and Linux, the currently logged in user can be identified with w and who. On macOS the dscl . list /Users | grep -v '_' command can also be used to enumerate user accounts. Environment variables, such as %USERNAME% and $USER, may also be used to access this information. On network devices, Network Device CLI commands such as `show users` and `show ssh` can be used to display users currently logged into the device.
Detection coverage (46)
- Potential Dridex Activity critical
- SharpHound Recon Sessions high
- Possible DCSync Attack high
- User Discovery And Export Via Get-ADUser Cmdlet medium
- System Owner or User Discovery - Linux low
- ESXi System Information Discovery Via ESXCLI medium
- ESXi VM List Discovery Via ESXCLI medium
- Cisco Discovery low
- ESXi Network Configuration Discovery Via ESXCLI medium
- ESXi VSAN Information Discovery Via ESXCLI medium
- ESXi Storage Information Discovery Via ESXCLI medium
- Get-ADUser Enumeration Using UserAccountControl Flags medium
- Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell medium
- Suspicious PowerShell Get Current User low
- User Discovery And Export Via Get-ADUser Cmdlet - PowerShell medium
- HackTool - SharpLdapWhoami Execution high
- HackTool - SharpView Execution high
- Computer Discovery And Export Via Get-ADComputer Cmdlet medium
- Renamed Whoami Execution critical
- Local Accounts Discovery low
- WhoAmI as Parameter high
- Chopper Webshell Process Pattern high
- Whoami.EXE Execution From Privileged Process high
- Webshell Hacking Activity Patterns high
- Webshell Detection With Command Line Keywords high
- Enumerate All Information With Whoami.EXE medium
- Security Privileges Enumeration Via Whoami.EXE high
- Whoami.EXE Execution With Output Option medium
- Whoami.EXE Execution Anomaly medium
- Group Membership Reconnaissance Via Whoami.EXE medium
- Check Elevated CMD using whoami
- GetCurrent User with PowerShell
- GetCurrent User with PowerShell Script Block
- Linux Auditd Whoami User Discovery
- System User Discovery With Query
- System User Discovery With Whoami
- User Discovery With Env Vars PowerShell Script Block
- User Discovery With Env Vars PowerShell
- Windows Common Abused Cmd Shell Risk Behavior
- Windows WinPEAS PowerShell Script Execution
- Windows System Discovery Using Qwinsta
- Windows System Discovery Using ldap Nslookup
- Windows System User Privilege Discovery
- Windows System Remote Discovery With Query
- Windows System User Discovery Via Quser
- Linux Root Execution of id
Malware using this technique
- Revenge RAT
- DRATzarus
- TrickBot
- ShadowPad
- Squirrelwaffle
- Emotet
- NBTscan
- NDiskMonitor
- BOOKWORM
- BabyShark
- WellMess
- Kazuar
- MacMa
- RustyWater
- SslMM
- BLUELIGHT
- MgBot
- StrifeWater
- Bumblebee
- Cuckoo Stealer
- Dyre
- Woody RAT
- Diavol
- Epic
- POWERSTATS
- S-Type
- MarkiRAT
- Havoc
- Mosquito
- Unknown Logger
- Azorult
- Raccoon Stealer
- metaMain
- AuTo Stealer
- SMOKEDHAM
- PUBLOAD
- Exaramel for Linux
- RedLine Stealer
- LAMEHUG
- SysUpdate
- RATANKBA
- FlawedAmmyy
- Rising Sun
- UPPERCUT
- WINERACK
- Latrodectus
- SynAck
- XAgentOSX
- WINDSHIELD
- Koadic
Threat actors using this technique
- Kimsuky
- APT38
- Moonstone Sleet
- FIN8
- APT15
- Dragonfly
- MirrorFace
- Sandworm Team
- FIN7
- HAFNIUM
- Winter Vivern
- APT19
- FIN10
- APT32
- APT39
- APT37
- Lazarus Group
- Tropic Trooper
- APT27
- Earth Lusca
- APT35
- ZIRCONIUM
- Chimera
- Patchwork
- Stealth Falcon
- Volt Typhoon
- Aquatic Panda
- Gamaredon Group
- GALLIUM
- Conti
- APT41
- OilRig
- HEXANE
- Windshift
- Medusa Ransomware
- MuddyWater
- Storm-1811
- Sidewinder
- APT3