1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1087 Account Discovery — Detection Rules

Detection workspace for T1087 Account Discovery: 15 Sigma sources, 1 Atlas concepts and 1 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

T1087 Account Discovery

MATCH(process_or_api_operation IN account_enumeration_operations) AND actor NOT_IN approved_admin_tools -> ALERT

Anomaly models

ATT&CK analytic guidance

DET0587 Enumeration of User or Account Information Across Platforms

AN1612 Analytic 1612

Detection of processes performing local or domain account enumeration by invoking account directory queries or security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward.

AN1613 Analytic 1613

Enumeration of users and groups through suspicious shell commands or unauthorized access to /etc/passwd or /etc/shadow.

AN1614 Analytic 1614

Detection of account enumeration through directory service queries or system utilities accessing account metadata stores, followed by structured enumeration output.

AN1615 Analytic 1615

Detection of enumeration of identity entities through cloud provider APIs where principals retrieve account metadata such as IAM users or roles in rapid succession.

AN1616 Analytic 1616

Detection of identity directory enumeration through API calls or administrative queries retrieving multiple account objects within a short interval.

AN1617 Analytic 1617

Detection of enumeration activity when system processes query ESXi host account configuration or management APIs to retrieve user account listings.

AN1618 Analytic 1618

Account enumeration via bulk access to user directory features or hidden APIs.

AN1619 Analytic 1619

Account discovery via VBA macros, COM objects, or embedded scripting.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1087 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Connected anomaly research

Curated research views reached through an exact source technique, a catalog model, or a reviewed collection reference. These are navigation associations, not claims of detector effectiveness or sensor equivalence.

Telemetry contracts · Maintained query examples · Validation and blind spots

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.