T1087.001 - Local Account
Sub-technique
Tattiche:
Discovery
Discovery
Piattaforme:
ESXi Linux macOS Windows
ESXi Linux macOS Windows
Rilevamento:
Not specified
Not specified
Description:
Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior.
Commands such as <code>net user</code> and <code>net localgroup</code> of the [Net](https://attack.mitre.org/software/S0039) utility and <code>id</code> and <code>groups</code> on macOS and Linux can list local users and groups.(Citation: Mandiant APT1)(Citation: id man page)(Citation: groups man page) On Linux, local users can also be enumerated through the use of the <code>/etc/passwd</code> file. On macOS, the <code>dscl . list /Users</code> command can be used to enumerate local accounts. On ESXi servers, the `esxcli system account list` command can list local user accounts.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)
Commands such as <code>net user</code> and <code>net localgroup</code> of the [Net](https://attack.mitre.org/software/S0039) utility and <code>id</code> and <code>groups</code> on macOS and Linux can list local users and groups.(Citation: Mandiant APT1)(Citation: id man page)(Citation: groups man page) On Linux, local users can also be enumerated through the use of the <code>/etc/passwd</code> file. On macOS, the <code>dscl . list /Users</code> command can be used to enumerate local accounts. On ESXi servers, the `esxcli system account list` command can list local user accounts.(Citation: Crowdstrike Hypervisor Jackpotting Pt 2 2021)
Usato da Attori (18)
APT1
Nation-state
Nation-state
APT3
Nation-state
Nation-state
Turla
Nation-state
Nation-state
Poseidon Group
Unknown
Unknown
OilRig
Nation-state
Nation-state
APT32
Nation-state
Nation-state
APT41
Nation-state
Nation-state
Fox Kitten
Unknown
Unknown
APT42
Nation-state
Nation-state
Volt Typhoon
Unknown
Unknown
Medusa Group
Unknown
Unknown
admin@338
Unknown
Unknown
Ke3chang
Unknown
Unknown
Chimera
Unknown
Unknown
Moses Staff
Unknown
Unknown
RedCurl
Unknown
Unknown
Threat Group-3390
Unknown
Unknown
Lotus Blossom
Unknown
Unknown
Malware (20)
Metadata
| MITRE ID: | T1087.001 |
| STIX ID: | attack-pattern--25659dd6-ea12-... |
| Piattaforme: | ESXi, Linux, macOS, Windows |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 16:00 |