T1087.002 Domain Account — ATT&CK Technique
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges. Commands such as net user /domain and net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain users and groups. PowerShell cmdlets including Get-ADUser and Get-ADGroupMember may enumerate members of Active Directory groups.
Detection coverage (48)
- Net.EXE Execution low
- PUA - Suspicious ActiveDirectory Enumeration Via AdFind.EXE high
- PUA - AdFind.EXE Execution medium
- PUA - AdFind Suspicious Execution high
- Potential Active Directory Reconnaissance/Enumeration Via LDAP medium
- AD Privileged Users or Groups Reconnaissance high
- Potential AD User Enumeration From Non-Machine Account medium
- Reconnaissance Activity high
- BloodHound Collection Files high
- ADExplorer Writing Complete AD Snapshot Into .dat File medium
- Malicious PowerShell Commandlets - PoshModule high
- Active Directory Computers Enumeration With Get-AdComputer low
- Malicious PowerShell Commandlets - ScriptBlock high
- Active Directory Structure Export Via Csvde.EXE medium
- HackTool - Bloodhound/Sharphound Execution high
- Suspicious Group And Account Reconnaissance Activity Using Net.EXE medium
- Malicious PowerShell Commandlets - ProcessCreation high
- Renamed AdFind Execution high
- Suspicious Active Directory Database Snapshot Via ADExplorer high
- Suspicious Use of PsLogList medium
- Active Directory Database Snapshot Via ADExplorer medium
- AdsiSearcher Account Discovery
- Detect AzureHound Command-Line Arguments
- Detect AzureHound File Modifications
- Detect SharpHound Command-Line Arguments
- Detect SharpHound File Modifications
- Detect SharpHound Usage
- Domain Account Discovery with Dsquery
- Domain Account Discovery with Wmic
- Get ADUser with PowerShell
- Get ADUser with PowerShell Script Block
- Get DomainUser with PowerShell
- Get DomainUser with PowerShell Script Block
- GetWmiObject DS User with PowerShell Script Block
- GetWmiObject DS User with PowerShell
- Network Traffic to Active Directory Web Services Protocol
- SchCache Change By App Connect And Create ADSI Object
- Windows AD Abnormal Object Access Activity
- Windows AD Privileged Object Access Activity
- Windows Domain Account Discovery Via Get-NetComputer
- Windows Find Interesting ACL with FindInterestingDomainAcl
- Windows Find Domain Organizational Units with GetDomainOU
- Windows Forest Discovery with GetForestDomain
- Windows Get Local Admin with FindLocalAdminAccess
- Windows Linked Policies In ADSI Discovery
- Windows Root Domain linked policies Discovery
- Windows SOAPHound Binary Execution
- Windows Suspect Process With Authentication Traffic
Malware using this technique
- Stuxnet
- POWRUNER
- Bankshot
- DUSTTRAP
- RustyWater
- BlackCat
- IcedID
- Sykipot
- Latrodectus
- Bazar
- CrackMapExec
- MgBot
- Cobalt Strike
- Valak
- BoomBox
- LAMEHUG
- IceApple
- Qilin
- SoreFang
- AdFind
- OSInfo
- Net
- BloodHound
- SILENTTRINITY
- Empire
- dsquery
- PoshC2
- Brute Ratel C4