1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1033 System Owner/User Discovery — Detection Rules

Detection workspace for T1033 System Owner/User Discovery: 29 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0093 Behavioral Detection of User Discovery via Local and Remote Enumeration

AN0254 Analytic 0254

Adversary launches built-in system tools (e.g., whoami, query user, net user) or scripts that enumerate user account information via local execution or remote API queries (e.g., WMI, PowerShell).

AN0255 Analytic 0255

Adversary runs commands like `whoami`, `id`, `w`, or `cat /etc/passwd` from non-interactive or scripting contexts to enumerate system user details.

AN0256 Analytic 0256

Adversary uses `dscl`, `who`, or environment variables like `$USER` to identify accounts or sessions via Terminal or malicious LaunchAgents.

AN0257 Analytic 0257

Adversary executes CLI commands like `show users`, `show ssh`, or attempts to dump AAA user lists from routers or switches.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1033 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.