Gather Victim Identity Information T1589
Tactic: Reconnaissance
Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, security question responses, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations.
Events covered
4 catalog events are tagged with this technique by at least one rule.
| Provider | Event | Title |
|---|---|---|
| Sysmon | Event ID 7 | Image loaded |
| Security-Auditing | Event ID 4768 | A Kerberos authentication ticket (TGT) was requested. |
| PowerShell | Event ID 4104 | Creating Scriptblock text (MessageNumber of MessageTotal). |
| Sysmon-for-Linux | Event ID 11 | File created |
Authoring guide
These 9 rules share fields, values, and exclusions.
Fields filtered most (18 distinct)
These fields appear most often in rule filters.
Top indicator values (37 distinct)
These values appear most often in rule predicates.
Rules under this technique
These vendors publish rules tagged with this technique.
Sigma 3 rules
- Azure AD Account Credential Leaked
- Potential Unconstrained Delegation Discovery Via Get-ADComputer - ScriptBlock
- SSHD Error Message CVE-2018-15473