System Owner/User Discovery T1033

Tactic: Discovery

Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.

Events covered

16 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 84 rules share fields, values, and exclusions.

Fields filtered most (51 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine39contains 27, regex_match 9, ends_with 2, eq 2, in 1, is_not_null 1, match 1 list, get, (?i)((tracert)|(query)|(net\s+((localgroup)|(group)|(conf..., -filter *, /c
process_name32eq 22, in 6, regex_match 3, contains 1, starts_with 1, wildcard 1arp.exe, dscl, id, whoami.exe, atbroker.exe
Image25ends_with 21, eq 2, starts_with 2, is_not_null 1, regex_match 1, wildcard 1\whoami.exe, /esxcli, \cmd.exe, \net.exe, \powershell.exe
OriginalFileName19eq 18, contains 1whoami.exe, powershell.exe, pwsh.dll, query.exe, quser.exe
event.type19eq 19start
host.os.type15eq 15
EventType14eq 8, in 6exec, exec_event, ProcessRollup2, executed, fork
EventID12eq 124104, 1, 4688, 4103
parent_process_name12eq 6, in 5, regex_match 1bash, sh, zsh, (?i)(powershell\.exe)|(cmd\.exe), acrobat.exe
ParentImage8ends_with 5, contains 2, eq 2, starts_with 2, is_not_null 1, is_null 1-tomcat-, \caddy.exe, \httpd.exe, -, /volumes/
ScriptBlockText8contains 6, in 2, match 1 -filter *, | select , $env:username, [system.environment]::username, >
process.args7eq 5, in 3, contains 2, wildcard 2%appdata%, %homepath%, %localappdata%, */bin/*sh*, *import*pty*spawn*
dc_process_name6gt 62, 1
Type3eq 3
event.category3eq 3process

Top indicator values (765 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
191078
Imageends_with
\whoami.exe
1019
Imageends_with
/esxcli
59
OriginalFileNameeq
whoami.exe
99
process_nameeq
whoami.exe
912
process_nameeq
quser.exe
610
process_nameeq
qwinsta.exe
69
process_nameeq
dsget.exe
58
process_nameeq
dsquery.exe
512
process_nameeq
net.exe
528
process_nameeq
net1.exe
539
process_nameeq
powershell.exe
5184
process_nameeq
arp.exe
49
process_nameeq
cmd.exe
4121
process_nameeq
gpresult.exe
47
process_nameeq
hostname.exe
47
process_nameeq
ipconfig.exe
410
process_nameeq
nbtstat.exe
49
process_nameeq
netsh.exe
421
process_nameeq
netstat.exe
49
process_nameeq
nltest.exe
411
EventTypeeq
exec
7576
EventIDeq
4104
6269
EventTypein
exec
6201
EventTypein
exec_event
5149
EventTypein
start
5163
process_namein
whoami
614
CommandLinecontains
get
44
CommandLinecontains
list
44
dc_process_namegt
2
44

Exclusions (184 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
CommandLineregex_match
(?i)\x5cSplunkUniversalForwarder\x5c(etc|bin)\x5c
2
userregex_match
\$$
2
CommandLinecontains
rmdir
1
CommandLinecontains
.dll
1
CommandLinecontains
/active
1
CommandLinecontains
/add
1
CommandLinecontains
/delete
1
CommandLinecontains
/domain
1
CommandLinecontains
/expires
1
CommandLinecontains
/passwordreq
1
CommandLinecontains
/scriptpath
1
CommandLinecontains
/times
1
CommandLinecontains
/workstations
1
CommandLinein
*/server:127.0.0.1*
1
CommandLinein
*/server:localhost*
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 30 rules

Elastic 23 rules

Splunk 27 rules

Kusto 1 rule

YARA-L 3 rules