Account Discovery T1087

Tactic: Discovery

Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts exist, which can aid in follow-on behavior such as brute-forcing, spear-phishing attacks, or account takeovers (e.g., Valid Accounts).

Events covered

43 catalog events are tagged with this technique by at least one rule.

ProviderEventTitle
SysmonEvent ID 1Process creation
SysmonEvent ID 3Network connection
SysmonEvent ID 7Image loaded
SysmonEvent ID 11FileCreate
Security-AuditingEvent ID 4624An account was successfully logged on.
Security-AuditingEvent ID 4625An account failed to log on.
Security-AuditingEvent ID 4661A handle to an object was requested.
Security-AuditingEvent ID 4662An operation was performed on an object.
Security-AuditingEvent ID 4672Special privileges assigned to new logon.
Security-AuditingEvent ID 4688A new process has been created.
Security-AuditingEvent ID 4769A Kerberos service ticket was requested.
Security-AuditingEvent ID 4776The domain controller attempted to validate the credentials for an account.
Security-AuditingEvent ID 4798A user's local group membership was enumerated.
Security-AuditingEvent ID 4799A security-enabled local group membership was enumerated.
Security-AuditingEvent ID 5136A directory service object was modified.
Defender-DeviceEventsCreateRemoteThreadApiCallCreateRemoteThread API call
Defender-DeviceEventsLdapSearchLDAP search
Defender-DeviceEventsNtAllocateVirtualMemoryRemoteApiCallRemote virtual memory allocation (NtAllocateVirtualMemory)
Defender-DeviceEventsMemoryRemoteProtectRemote virtual memory protection change
Defender-DeviceEventsNtMapViewOfSectionRemoteApiCallRemote section map (NtMapViewOfSection)
Defender-DeviceEventsQueueUserApcRemoteApiCallRemote APC queued (QueueUserApc)
Defender-DeviceEventsSetThreadContextRemoteApiCallRemote thread context change (SetThreadContext)
Defender-DeviceEventsNtAllocateVirtualMemoryApiCallNtAllocateVirtualMemory API call
Defender-DeviceEventsNtProtectVirtualMemoryApiCallNtProtectVirtualMemory API call
Defender-DeviceInfoanyDevice information
Defender-DeviceNetworkEventsanyNetwork activity
Defender-DeviceNetworkEventsConnectionSuccessConnection succeeded
Defender-DeviceNetworkInfoanyDevice network configuration
Defender-DeviceProcessEventsanyProcess activity
Defender-IdentityQueryEventsLDAP queryLDAP query
ESFexecProcess Execution
Linux-AuditdEvent ID 1101USER_ACCT
Linux-AuditdEvent ID 1103CRED_ACQ
Linux-AuditdEvent ID 1105USER_START
Linux-AuditdEvent ID 1106USER_END
Linux-AuditdEvent ID 1123USER_CMD
LDAP-ClientEvent ID 30LDAP search request
PowerShellEvent ID 4103Payload Context: ContextInfo User Data: UserData.
PowerShellEvent ID 4104Creating Scriptblock text (MessageNumber of MessageTotal).
PowerShellEvent ID 600Event ID 600
PowerShellEvent ID 800Event ID 800
RPCFWEvent ID 3An RPC server function was called.
Sysmon-for-LinuxEvent ID 1Process Create

Authoring guide

These 219 rules share fields, values, and exclusions.

Fields filtered most (201 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
CommandLine60contains 39, regex_match 15, in 3, ends_with 2, eq 2, is_not_null 2, match 2(?i)((tracert)|(query)|(net\s+((localgroup)|(group)|(conf..., (?i)searchroot|objectcategory=|userenum, oudmp , (?i)((netstat)|(netsh)|(schtasks)|(tasklist)|(driverquery..., (?i)((whoami)|(dir)|(hostname)|(hostname)|(systeminfo)|(i...
EventID55eq 554104, 4688, 1, 4103, 4662
process_name32eq 21, regex_match 7, starts_with 2, wildcard 2, contains 1, ends_with 1, in 1net1.exe, cmd.exe, dsquery.exe, net.exe, powershell.exe
Image26ends_with 22, eq 2, contains 1, regex_match 1, starts_with 1\net.exe, \net1.exe, \adexp.exe, \adexplorer.exe, \adexplorer64.exe
OriginalFileName24eq 24net1.exe, net.exe, adexp, adfind.exe, wmic.exe
ScriptBlockText22contains 19, in 5, eq 1[adsisearcher], get-netuser, get-wmiobject, *accountexpires*, *lastlogoff*
host.os.type15eq 14, in 1
data_stream.dataset13eq 12, in 1azure.aadgraphactivitylogs, aws.cloudtrail, azure.signinlogs, azure.activitylogs, azure.auditlogs
Type12eq 12
event.type12eq 11, in 1start, process_started
process.Ext.api.name12eq 12ldap_search
process.Ext.api.parameters.search_filter12wildcard 7, eq 5, contains 2(&(objectCategory=person)(objectClass=user)(directReports..., (&(&(&(&(samAccountType=805306369)(!(primaryGroupId=516))..., (&(&(objectCategory=person)(objectClass=user))(|(descript..., (&(objectCategory=Computer)(!userAccountControl:1.2.840.1..., (&(objectCategory=Computer)(ms-MCS-AdmPwd=?))
type10eq 9, in 1, like 1policy, user, %CRED_ACQ%, %CRED_DISP%, %CRED_REFR%
user.id9ne 7, contains 1, is_not_null 1S-1-5-18, :i-
EventType8eq 6, in 1, ne 1exec, getcalleridentity, describecapacityreservations, describeorganization, describeorgnanizationalunit

Top indicator values (2409 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
EventIDeq
4104
24269
EventIDeq
4688
13317
EventIDeq
1
8241
EventIDeq
4103
6105
EventIDeq
4662
415
process.Ext.api.nameeq
ldap_search
1214
event.typeeq
start
111078
OriginalFileNameeq
net1.exe
844
OriginalFileNameeq
net.exe
731
OriginalFileNameeq
wmic.exe
480
process_nameeq
net1.exe
739
process_nameeq
net.exe
628
process_nameeq
cmd.exe
5121
user.idne
S-1-5-18
736
DeviceProducteq
X Series
67
DeviceVendoreq
Vectra Networks
67
typeeq
policy
66
DestinationPorteq
9389
55
Imageends_with
\net.exe
549
Imageends_with
\net1.exe
547
data_stream.dataseteq
azure.aadgraphactivitylogs
56
data_stream.dataseteq
aws.cloudtrail
4169
CommandLinecontains
user
417
DeviceEventClassIDne
asc
44
DeviceEventClassIDne
audit
44
DeviceEventClassIDne
campaigns
44
DeviceEventClassIDne
health
44
DeviceEventClassIDne
hsc
44
OperationNamecontains
update a partner cross-tenant access setting
44
SubjectUserNameends_with
$
45

Exclusions (254 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
Imagewildcard
?:\program files\azure advanced threat protection sensor\*\microsoft.tri.sensor.exe
10
Imagewildcard
?:\windows\adfs\microsoft.identityserver.servicehost.exe
10
Imagewildcard
?:\windows\adws\microsoft.activedirectory.webservices.exe
8
Imagewildcard
?:\windows\system32\lsass.exe
4
SubjectUserNameends_with
$
4
process.code_signature.trustedeq
true
4
user.ideq
s-1-5-18
3
user.idin
S-1-5-18
3
user.idin
S-1-5-19
3
user.idin
S-1-5-20
3
CommandLinecontains
add
2
CommandLineregex_match
(?i)\x5cSplunkUniversalForwarder\x5c(etc|bin)\x5c
2
Imagestarts_with
c:\windows\system32\windowspowershell\
2
Imagestarts_with
c:\windows\syswow64\windowspowershell\
2
Signaturein
Azul Systems, Inc.
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 52 rules

Elastic 45 rules

Splunk 76 rules

Kusto 37 rules

YARA-L 1 rule

Panther 8 rules