System Owner/User Discovery T1033
Tactic: Discovery
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions.
Events covered
16 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 1 | Process creation |
| Security-Auditing | Event ID 4688 | A new process has been created. |
| Defender-DeviceEvents | LdapSearch | LDAP search |
| ESF | exec | Process Execution |
| ESF | write | File Write |
| Linux-Auditd | Event ID 1101 | USER_ACCT |
| Linux-Auditd | Event ID 1103 | CRED_ACQ |
| Linux-Auditd | Event ID 1105 | USER_START |
| Linux-Auditd | Event ID 1106 | USER_END |
| Linux-Auditd | Event ID 1123 | USER_CMD |
| Linux-Auditd | Event ID 1300 | SYSCALL |
| Linux-Auditd | Event ID 1309 | EXECVE |
| PowerShell | Event ID 4103 | Payload Context: ContextInfo User Data: UserData. |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
| RPCFW | Event ID 3 | An RPC server function was called. |
| Sysmon-for-Linux | Event ID 1 | Process Create |
Authoring guide
These 84 rules share fields, values, and exclusions.
Fields filtered most (51 distinct)
These fields appear most often in rule filters.
Top indicator values (765 distinct)
These values appear most often in rule predicates.
Exclusions (184 distinct)
These values appear most often in top-level exclusions.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 30 rules
- Chopper Webshell Process Pattern
- Cisco Discovery
- Computer Discovery And Export Via Get-ADComputer Cmdlet
- Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell
- Enumerate All Information With Whoami.EXE
- ESXi Network Configuration Discovery Via ESXCLI
- ESXi Storage Information Discovery Via ESXCLI
- ESXi System Information Discovery Via ESXCLI
- ESXi VM List Discovery Via ESXCLI
- ESXi VSAN Information Discovery Via ESXCLI
- Get-ADUser Enumeration Using UserAccountControl Flags
- Group Membership Reconnaissance Via Whoami.EXE
- HackTool - SharpLdapWhoami Execution
- HackTool - SharpView Execution
- Local Accounts Discovery
- Possible DCSync Attack
- Potential Dridex Activity
- Renamed Whoami Execution
- Security Privileges Enumeration Via Whoami.EXE
- SharpHound Recon Sessions
- Suspicious PowerShell Get Current User
- System Owner or User Discovery - Linux
- User Discovery And Export Via Get-ADUser Cmdlet
- User Discovery And Export Via Get-ADUser Cmdlet - PowerShell
- Webshell Detection With Command Line Keywords
- Webshell Hacking Activity Patterns
- WhoAmI as Parameter
- Whoami.EXE Execution Anomaly
- Whoami.EXE Execution From Privileged Process
- Whoami.EXE Execution With Output Option
Elastic 23 rules
- Account Discovery Command via SYSTEM Account
- AWS STS GetCallerIdentity API Called for the First Time
- Discovery Command Output Written to Suspicious File
- Dscl Execution via Osascript
- Enumeration Command Spawned via WMIPrvSE
- Initial Access Discovery via Applet Executable
- Passwordless Sudo Probing
- Potentially Suspicious Process Started via tmux or screen
- PowerShell Suspicious Discovery Related Windows API Functions
- Privilege Boundary Enumeration Detected via Defend for Containers
- Sudo Command Enumeration Detected
- Suspicious Dscl Auth Validation
- Suspicious JetBrains TeamCity Child Process
- Suspicious MS Office Child Process
- Suspicious PDF Reader Child Process
- Suspicious React Server Child Process
- Suspicious System Commands Executed by Previously Unknown Executable
- System Owner/User Discovery Linux
- Unusual Linux User Discovery Activity
- Unusual User Privilege Enumeration via id
- User Discovery Command Execution from Volume Mount
- Whoami Process Activity
- Windows Account or Group Discovery
Splunk 27 rules
- Check Elevated CMD using whoami
- Common Recon Commands in Short Burst (Sysmon)
- Common Recon Commands in Short Burst (Windows Event Log)
- Common Reconnaissance Commands (PowerShell)
- Common Reconnaissance Commands (Sysmon)
- Common Reconnaissance Commands (Windows Event Log)
- GetCurrent User with PowerShell
- GetCurrent User with PowerShell Script Block
- Linux Auditd Whoami User Discovery
- Linux Enumeration Techniques
- Linux Root Execution of id
- PowerView_SharpView Commands (PowerShell)
- System Owner_User Discovery - Windows (PowerShell)
- System Owner_User Discovery - Windows (Sysmon)
- System Owner_User Discovery - Windows (Windows Event Log)
- System User Discovery With Query
- System User Discovery With Whoami
- User Discovery via Environment Variables - PowerShell (PowerShell)
- User Discovery With Env Vars PowerShell
- User Discovery With Env Vars PowerShell Script Block
- Windows Common Abused Cmd Shell Risk Behavior
- Windows System Discovery Using ldap Nslookup
- Windows System Discovery Using Qwinsta
- Windows System Remote Discovery With Query
- Windows System User Discovery Via Quser
- Windows System User Privilege Discovery
- Windows WinPEAS PowerShell Script Execution