1200KM / simulation
T1033 System Owner/User Discovery — Attack Simulation
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include…
Technique description
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- GetCurrent User with PowerShell Script
Procedure 1392bd0f-5d5a-429e-81d9-eb9d4d4d5b3b; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Find computers where user has session - Stealth mode (PowerView)
Procedure 29857f27-a36f-4f7e-8084-4557cd6207ca; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Owner/User Discovery
Procedure 2a9b677d-a230-44f4-ad86-782df1ef108c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Discovery - SocGholish whoami
Procedure 3d257a03-eb80-41c5-b744-bb37ac7f65c7; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- System Owner/User Discovery
Procedure 4c4959bf-addf-4b4a-be86-8d09cc1857aa; elevation not declared required; cleanup not declared. Not executed or individually validated.
- User Discovery - whoami
Procedure aab580c7-cc30-4a7c-b5a9-46a29066b022; elevation not declared required; cleanup not declared. Not executed or individually validated.
- System Owner/User Discovery Using Command Prompt
Procedure ba38e193-37a6-4c41-b214-61b33277fe36; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- User Discovery With Env Vars PowerShell Script
Procedure dcb6cdee-1fb0-4087-8bf8-88cfd136ba51; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
- Ke3chang · G0004
- APT3 · G0022
- Threat Group-3390 · G0027
- Lazarus Group · G0032
- Sandworm Team · G0034
- Dragonfly · G0035
- Stealth Falcon · G0038
- Patchwork · G0040
- FIN7 · G0046
- Gamaredon Group · G0047
- OilRig · G0049
- APT32 · G0050
- FIN10 · G0051
- Magic Hound · G0059
- FIN8 · G0061
- APT37 · G0067
- MuddyWater · G0069
- APT19 · G0073
- Tropic Trooper · G0081
- APT38 · G0082
- APT39 · G0087
- GALLIUM · G0093
- Kimsuky · G0094
- APT41 · G0096
- Wizard Spider · G0102
- Windshift · G0112
- Chimera · G0114
- Sidewinder · G0121
- HAFNIUM · G0125
- ZIRCONIUM · G0128
- Aquatic Panda · G0143
- HEXANE · G1001
- Earth Lusca · G1006
- LuminousMoth · G1014
- Volt Typhoon · G1017
- Winter Vivern · G1035
- Moonstone Sleet · G1036
- Storm-1811 · G1046
- Medusa Group · G1051
- MirrorFace · G1054
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.