T1087.002 - Domain Account
Sub-technique
Tattiche:
Discovery
Discovery
Piattaforme:
Linux macOS Windows
Linux macOS Windows
Rilevamento:
Not specified
Not specified
Description:
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.
Commands such as <code>net user /domain</code> and <code>net group /domain</code> of the [Net](https://attack.mitre.org/software/S0039) utility, <code>dscacheutil -q group</code> on macOS, and <code>ldapsearch</code> on Linux can list domain users and groups. [PowerShell](https://attack.mitre.org/techniques/T1059/001) cmdlets including <code>Get-ADUser</code> and <code>Get-ADGroupMember</code> may enumerate members of Active Directory groups.(Citation: CrowdStrike StellarParticle January 2022)
Commands such as <code>net user /domain</code> and <code>net group /domain</code> of the [Net](https://attack.mitre.org/software/S0039) utility, <code>dscacheutil -q group</code> on macOS, and <code>ldapsearch</code> on Linux can list domain users and groups. [PowerShell](https://attack.mitre.org/techniques/T1059/001) cmdlets including <code>Get-ADUser</code> and <code>Get-ADGroupMember</code> may enumerate members of Active Directory groups.(Citation: CrowdStrike StellarParticle January 2022)
Usato da Attori (20)
Turla
Nation-state
Nation-state
FIN7
Criminal
Criminal
Poseidon Group
Unknown
Unknown
FIN6
Unknown
Unknown
OilRig
Nation-state
Nation-state
MuddyWater
Nation-state
Nation-state
MUSTANG PANDA
Nation-state
Nation-state
WIZARD SPIDER
Nation-state
Nation-state
APT41
Nation-state
Nation-state
Fox Kitten
Unknown
Unknown
FIN13
Unknown
Unknown
ToddyCat
Unknown
Unknown
Volt Typhoon
Unknown
Unknown
Scattered Spider
Unknown
Unknown
Storm-0501
Unknown
Unknown
Dragonfly
Unknown
Unknown
Sandworm Team
Unknown
Unknown
Ke3chang
Unknown
Unknown
BRONZE BUTLER
Unknown
Unknown
Storm-1811
Unknown
Unknown
Malware (20)
Metadata
| MITRE ID: | T1087.002 |
| STIX ID: | attack-pattern--21875073-b0ee-... |
| Piattaforme: | Linux, macOS, Windows |
| Created: | 13/01/2026 17:48 |
| Updated: | 06/03/2026 16:00 |