1200KM / simulation
T1087.001 Local Account — Attack Simulation
Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior. Commands such as net user and net localgroup of the Net utility and id and groups on macOS and Linux can list local users and groups. On Linux, local users can also be enumerated through the use of the /etc/passwd file. On macOS, the dscl . list /Users command can…
Technique description
Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior. Commands such as net user and net localgroup of the Net utility and id and groups on macOS and Linux can list local users and groups. On Linux, local users can also be enumerated through the use of the /etc/passwd file. On macOS, the dscl . list /Users command can…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Show if a user account has ever logged in remotely
Procedure 0f0b6a29-08c3-44ad-a30b-47fd996b2110; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Enumerate users and groups
Procedure 319e9f6c-7a9e-432e-8c62-9385c803b6f2; elevation not declared required; cleanup not declared. Not executed or individually validated.
- List opened files by user
Procedure 7e46c7a5-0142-45be-a858-1a3ecb4fd3cb; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Enumerate all accounts on Windows (Local)
Procedure 80887bec-5a9b-4efc-a81d-f83eb2eb32ab; elevation not declared required; cleanup not declared. Not executed or individually validated.
- ESXi - Local Account Discovery via ESXCLI
Procedure 9762ac6e-aa60-4449-a2f0-cbbd0e1fd22c; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Enumerate logged on users via CMD (Local)
Procedure a138085e-bfe5-46ba-a242-74a6fb884af3; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Enumerate all accounts via PowerShell (Local)
Procedure ae4b6361-b5f8-46cb-a3f9-9cf108ccfe7b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- View accounts with UID 0
Procedure c955a599-3653-4fe5-b631-f11c00eb0397; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- Enumerate users and groups
Procedure e6f36545-dc1e-47f0-9f48-7f730f54a02e; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Enumerate all accounts (Local)
Procedure f8aab3dd-5990-4bf8-b8ab-2226c951696f; elevation not declared required; cleanup present, not reviewed. Not executed or individually validated.
- View sudoers access
Procedure fed9be70-0186-4bde-9f8a-20945f9370c2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.