Gather Victim Identity Information T1589

Tactic: Reconnaissance

Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, security question responses, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations.

Events covered

4 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 9 rules share fields, values, and exclusions.

Fields filtered most (18 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
EventID2eq 24768, 7
Status2eq 20x6, 200
Channel1eq 1, in 1
CommadCount1ge 18
ImageLoaded1ends_with 1\\samcli.dll, \\samlib.dll
OriginalFileName1eq 1samcli.dll, samlib.dll
ScriptBlockText1match 1-ldapfilter*(useraccountcontrol:1.2.840.113556.1.4.803:=524288), -properties*msds-allowedtodelegateto, -properties*principalsallowedtodelegatetoaccount
TargetFilename1in 1*.backup_ld.so, *.boot.sh, *.logpam
TargetUserName1ne 1*$
Timestamp1cross_field_compare 1timestamp
UriPath1contains 1/api/users/activity
aws::userAgent1starts_with 1aws-cli
azure_ad::risk_event_types1eq 1leakedcredentials
command1contains 1suspiciouscommands
eventtype1eq 1

Top indicator values (37 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
CommadCountge
8
1
EventIDeq
4768
114
EventIDeq
7
141
ImageLoadedends_with
\\samcli.dll
1
ImageLoadedends_with
\\samlib.dll
1
OriginalFileNameeq
samcli.dll
1
OriginalFileNameeq
samlib.dll
1
ScriptBlockTextmatch
-ldapfilter*(useraccountcontrol:1.2.840.113556.1.4.803:=524288)
1
ScriptBlockTextmatch
-properties*msds-allowedtodelegateto
1
ScriptBlockTextmatch
-properties*principalsallowedtodelegatetoaccount
1
ScriptBlockTextmatch
-properties*trustedfordelegation
1
ScriptBlockTextmatch
-properties*trustedtoauthfordelegation
1
Statuseq
0x6
15
Statuseq
200
12
TargetFilenamein
*.backup_ld.so
1
TargetFilenamein
*.boot.sh
1
TargetFilenamein
*.logpam
1
TargetFilenamein
*/lib/libdsx.so
1
TargetFilenamein
*/lib/libseconf
1
TargetFilenamein
*/lib/libseconf/.pts
1
TargetFilenamein
*/lib/libseconf/local.txt
1
TargetFilenamein
*/lib/locate /.pts
1
TargetFilenamein
*/lib/locate/local.txt
1
TargetFilenamein
*/libseconf/.ports
1
TargetFilenamein
*/var/log/remote.txt
1
TargetFilenamein
*rkload
1
TargetFilenamein
*sshpass.txt
1
TargetFilenamein
*sshpass2.txt
1
TargetUserNamene
*$
114
Timestampcross_field_compare
timestamp
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 3 rules

Splunk 3 rules

Kusto 2 rules

Panther 1 rule