T1033 System Owner/User Discovery — ATT&CK Technique
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Various utilities and commands may acquire this information, including whoami. In macOS and Linux, the currently logged in user can be identified with w and who. On macOS the dscl . list /Users | grep -v '_' command can also be used to enumerate user accounts. Environment variables, such as %USERNAME% and $USER, may also be used to access this information. On network devices, Network Device CLI commands such as `show users` and `show ssh` can be used to display users currently logged into the device.
Detection coverage (46)
- Potential Dridex Activity critical
- SharpHound Recon Sessions high
- Possible DCSync Attack high
- User Discovery And Export Via Get-ADUser Cmdlet medium
- System Owner or User Discovery - Linux low
- ESXi System Information Discovery Via ESXCLI medium
- ESXi VM List Discovery Via ESXCLI medium
- Cisco Discovery low
- ESXi Network Configuration Discovery Via ESXCLI medium
- ESXi VSAN Information Discovery Via ESXCLI medium
- ESXi Storage Information Discovery Via ESXCLI medium
- Get-ADUser Enumeration Using UserAccountControl Flags medium
- Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell medium
- Suspicious PowerShell Get Current User low
- User Discovery And Export Via Get-ADUser Cmdlet - PowerShell medium
- HackTool - SharpLdapWhoami Execution high
- HackTool - SharpView Execution high
- Computer Discovery And Export Via Get-ADComputer Cmdlet medium
- Renamed Whoami Execution critical
- Local Accounts Discovery low
- WhoAmI as Parameter high
- Chopper Webshell Process Pattern high
- Whoami.EXE Execution From Privileged Process high
- Webshell Hacking Activity Patterns high
- Webshell Detection With Command Line Keywords high
- Enumerate All Information With Whoami.EXE medium
- Security Privileges Enumeration Via Whoami.EXE high
- Whoami.EXE Execution With Output Option medium
- Whoami.EXE Execution Anomaly medium
- Group Membership Reconnaissance Via Whoami.EXE medium
- Check Elevated CMD using whoami
- GetCurrent User with PowerShell
- GetCurrent User with PowerShell Script Block
- Linux Auditd Whoami User Discovery
- System User Discovery With Query
- System User Discovery With Whoami
- User Discovery With Env Vars PowerShell Script Block
- User Discovery With Env Vars PowerShell
- Windows Common Abused Cmd Shell Risk Behavior
- Windows WinPEAS PowerShell Script Execution
- Windows System Discovery Using Qwinsta
- Windows System Discovery Using ldap Nslookup
- Windows System User Privilege Discovery
- Windows System Remote Discovery With Query
- Windows System User Discovery Via Quser
- Linux Root Execution of id
Malware using this technique
- TrickBot
- PowerDuke
- RCSession
- Spark
- SynAck
- Bumblebee
- Amadey
- NOKKI
- yty
- Backdoor.Oldrea
- IronWind
- Get2
- POWRUNER
- KOPILUWAK
- Linux Rabbit
- Exaramel for Linux
- HAWKBALL
- RedLeaves
- Felismus
- Havoc
- Chrommme
- GravityRAT
- InvisibleFerret
- HAPPYWORK
- WinMM
- TONESHELL
- LitePower
- PyDCrypt
- BOOKWORM
- SslMM
- Aria-body
- Emotet
- Crimson
- Turian
- BADHATCH
- Action RAT
- Clambling
- PureCrypter
- Prikormka
- PUBLOAD
- WellMess
- Woody RAT
- Mafalda
- Squirrelwaffle
- HexEval Loader
- AuTo Stealer
- Agent.btz
- SombRAT
- FlawedAmmyy
- Rifdoor
Threat actors using this technique
- APT38
- Medusa Ransomware
- Storm-2603
- HEXANE
- GALLIUM
- Kimsuky
- Volt Typhoon
- Patchwork
- APT41
- Dragonfly
- APT32
- HAFNIUM
- Gamaredon Group
- Storm-1811
- FIN7
- Sandworm Team
- Sidewinder
- APT35
- ZIRCONIUM
- APT39
- APT37
- OilRig
- APT27
- Tropic Trooper
- Aquatic Panda
- APT15
- Winter Vivern
- Stealth Falcon
- Chimera
- MirrorFace
- FIN10
- FIN8
- Windshift
- LuminousMoth
- Lazarus Group
- Earth Lusca
- Conti
- Moonstone Sleet
- MuddyWater
- APT3
- APT19