1200KM / detection
T1033 System Owner/User Discovery — Detection Rules
Detection workspace for T1033 System Owner/User Discovery: 29 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Possible DCSync Attack · test · high · {"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes, enable DRSR UUID (e3514235-4b06-11d1-ab04-00c04fc2dcd2) for \"dangerous\" opcodes (not 0,1 or 12) only from trusted IPs (DCs)"}
- SharpHound Recon Sessions · test · high · {"product":"rpc_firewall","category":"application","definition":"Requirements: install and apply the RPC Firewall to all processes with \"audit:true action:block uuid:4b324fc8-1670-01d3-1278-5a47bf6ee188 opnum:12"}
- System Owner or User Discovery - Linux · test · low · {"product":"linux","service":"auditd"}
- ESXi Network Configuration Discovery Via ESXCLI · test · medium · {"category":"process_creation","product":"linux"}
- ESXi Storage Information Discovery Via ESXCLI · test · medium · {"category":"process_creation","product":"linux"}
- ESXi System Information Discovery Via ESXCLI · test · medium · {"category":"process_creation","product":"linux"}
- ESXi VM List Discovery Via ESXCLI · test · medium · {"category":"process_creation","product":"linux"}
- ESXi VSAN Information Discovery Via ESXCLI · test · medium · {"category":"process_creation","product":"linux"}
- Cisco Discovery · test · low · {"product":"cisco","service":"aaa"}
- Get-ADUser Enumeration Using UserAccountControl Flags · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Computer Discovery And Export Via Get-ADComputer Cmdlet - PowerShell · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Suspicious PowerShell Get Current User · test · low · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- User Discovery And Export Via Get-ADUser Cmdlet - PowerShell · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - SharpLdapWhoami Execution · test · high · {"category":"process_creation","product":"windows"}
- HackTool - SharpView Execution · test · high · {"category":"process_creation","product":"windows"}
- Computer Discovery And Export Via Get-ADComputer Cmdlet · test · medium · {"category":"process_creation","product":"windows"}
- User Discovery And Export Via Get-ADUser Cmdlet · test · medium · {"category":"process_creation","product":"windows"}
- Renamed Whoami Execution · test · critical · {"category":"process_creation","product":"windows"}
- Local Accounts Discovery · test · low · {"category":"process_creation","product":"windows"}
- WhoAmI as Parameter · test · high · {"category":"process_creation","product":"windows"}
- Chopper Webshell Process Pattern · test · high · {"category":"process_creation","product":"windows"}
- Webshell Hacking Activity Patterns · test · high · {"category":"process_creation","product":"windows"}
- Webshell Detection With Command Line Keywords · test · high · {"category":"process_creation","product":"windows"}
- Enumerate All Information With Whoami.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Whoami.EXE Execution From Privileged Process · test · high · {"category":"process_creation","product":"windows"}
- Group Membership Reconnaissance Via Whoami.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Whoami.EXE Execution With Output Option · test · medium · {"category":"process_creation","product":"windows"}
- Whoami.EXE Execution Anomaly · test · medium · {"category":"process_creation","product":"windows"}
- Security Privileges Enumeration Via Whoami.EXE · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0093 Behavioral Detection of User Discovery via Local and Remote Enumeration
AN0254 Analytic 0254
Adversary launches built-in system tools (e.g., whoami, query user, net user) or scripts that enumerate user account information via local execution or remote API queries (e.g., WMI, PowerShell).
AN0255 Analytic 0255
Adversary runs commands like `whoami`, `id`, `w`, or `cat /etc/passwd` from non-interactive or scripting contexts to enumerate system user details.
AN0256 Analytic 0256
Adversary uses `dscl`, `who`, or environment variables like `$USER` to identify accounts or sessions via Terminal or malicious LaunchAgents.
AN0257 Analytic 0257
Adversary executes CLI commands like `show users`, `show ssh`, or attempts to dump AAA user lists from routers or switches.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT3 · G0022
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- Stealth Falcon · G0038
- Patchwork · G0040
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- FIN10 · G0051
- Magic Hound · G0059
- FIN8 · G0061
- APT37 · G0067
- MuddyWater · G0069
- APT19 · G0073
- Tropic Trooper · G0081
- APT38 · G0082
- APT39 · G0087
- GALLIUM · G0093
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Windshift · G0112
- Chimera · G0114
- Sidewinder · G0121
- HAFNIUM · G0125
- ZIRCONIUM · G0128
- Aquatic Panda · G0143
- HEXANE · G1001
- Earth Lusca · G1006
- LuminousMoth · G1014
- Volt Typhoon · G1017
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- Storm-1811 · G1046
- Medusa Group · G1051
- MirrorFace · G1054
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.