1200KM / detection
T1087.001 Local Account — Detection Rules
Detection workspace for T1087.001 Local Account: 12 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Local System Accounts Discovery - Linux · test · low · {"category":"process_creation","product":"linux"}
- Local System Accounts Discovery - MacOs · test · low · {"category":"process_creation","product":"macos"}
- Cisco Collect Data · test · low · {"product":"cisco","service":"aaa"}
- BloodHound Collection Files · test · high · {"product":"windows","category":"file_event"}
- Malicious PowerShell Commandlets - PoshModule · test · high · {"product":"windows","category":"ps_module","definition":"0ad03ef1-f21b-4a79-8ce8-e6900c54b65b"}
- Malicious PowerShell Commandlets - ScriptBlock · test · high · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- HackTool - Bloodhound/Sharphound Execution · test · high · {"category":"process_creation","product":"windows"}
- Suspicious Group And Account Reconnaissance Activity Using Net.EXE · test · medium · {"category":"process_creation","product":"windows"}
- Suspicious Reconnaissance Activity Using Get-LocalGroupMember Cmdlet · test · medium · {"category":"process_creation","product":"windows"}
- Malicious PowerShell Commandlets - ProcessCreation · test · high · {"category":"process_creation","product":"windows"}
- Local Accounts Discovery · test · low · {"category":"process_creation","product":"windows"}
- Suspicious Use of PsLogList · test · medium · {"category":"process_creation","product":"windows"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0303 Local Account Enumeration Across Host Platforms
AN0846 Analytic 0846
Adversary enumeration of local user accounts using Net.exe, WMI, or PowerShell.
AN0847 Analytic 0847
Enumeration of local users or groups via file access (/etc/passwd) or commands like id, groups.
AN0848 Analytic 0848
Enumeration of macOS local users using dscl, id, dscacheutil, or /etc/passwd access.
AN0849 Analytic 0849
Enumeration of local ESXi accounts using esxcli or vSphere API from unauthorized sessions.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.