1200KM / detection
T1069 Permission Groups Discovery — Detection Rules
Detection workspace for T1069 Permission Groups Discovery: 3 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Malicious PowerShell Commandlets - PoshModule · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Malicious PowerShell Commandlets - ScriptBlock · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- Malicious PowerShell Commandlets - ProcessCreation · test · high · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
T1069 Permission Groups Discovery
MATCH(process_or_api_operation IN group_enumeration_operations) AND actor NOT_IN approved_admin_tools -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0179 Behavioral Detection of Permission Groups Discovery
AN0507 Analytic 0507
Detection of adversary enumeration of domain or local group memberships via native tools such as net.exe, PowerShell, or WMI. This activity may precede lateral movement or privilege escalation.
AN0508 Analytic 0508
Detection of group enumeration using commands like 'id', 'groups', or 'getent group', often followed by privilege escalation or SSH lateral movement.
AN0509 Analytic 0509
Group membership checks via 'dscl', 'dscacheutil', or 'id', typically executed via terminal or automation scripts.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.