1200KM / simulation
T1069.002 Domain Groups — Attack Simulation
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators. Commands such as net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on…
Technique description
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators. Commands such as net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Elevated group enumeration using net group (Domain)
Procedure 0afb5163-8181-432e-9405-4322710c0c37; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Active Directory Enumeration with LDIFDE
Procedure 22cf8cb9-adb1-4e8c-80ca-7c723dfc8784; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Enumerate Active Directory Groups with Get-AdGroup
Procedure 3d1fcd2a-e51c-4cbe-8d84-9a843bad8dc8; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Get-ADUser Enumeration using UserAccountControl flags (AS-REP Roasting)
Procedure 43fa81fb-34bb-4b5f-867b-03c7dbe0e3d8; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Get-DomainGroupMember with PowerView
Procedure 46352f40-f283-4fe5-b56d-d9a71750e145; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Adfind - Query Active Directory Groups
Procedure 48ddc687-82af-40b7-8472-ff1e742e8274; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Get-DomainGroup with PowerView
Procedure 5a8a181c-2c8e-478d-a943-549305a01230; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Find Local Admins via Group Policy (PowerView)
Procedure 64fdb43b-5259-467a-b000-1b02c00e510a; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Permission Groups Discovery PowerShell (Domain)
Procedure 6d5d8c96-3d2a-4da9-9d6d-9a9d341899a7; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Enumerate Users Not Requiring Pre Auth (ASRepRoast)
Procedure 870ba71e-6858-4f6d-895c-bb6237f6121b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Enumerate Active Directory Groups with ADSISearcher
Procedure 9f4e344b-8434-41b3-85b1-d38f29d148d0; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Find machines where user has local admin access (PowerView)
Procedure a2d71eee-a353-4232-9f86-54f4288dd8c1; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Find local admins on all machines in domain (PowerView)
Procedure a5f0d9f8-d3c9-46c0-8378-846ddd6b1cbd; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Active Directory Domain Search Using LDAP - Linux (Ubuntu)/macOS
Procedure d58d749c-4450-4975-a9e9-8b1d562755c2; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Basic Permission Groups Discovery Windows (Domain)
Procedure dd66d77d-8998-48c0-8024-df263dc2ce5d; elevation not declared required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.