Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1033

T1033System Owner/User Discovery

T1033 — System Owner/User Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 18 detection use cases covering it and 4 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
18Use cases
4Articles
0Sub-techniques
1Tactic

Use cases covering this technique (18)

Check Elevated CMD using whoami ESCU actions · alerting P GetCurrent User with PowerShell ESCU actions · hunting P GetCurrent User with PowerShell Script Block ESCU actions · hunting P Linux Auditd Whoami User Discovery ESCU actions · hunting P System User Discovery With Query ESCU actions · hunting P System User Discovery With Whoami ESCU actions · hunting P User Discovery With Env Vars PowerShell ESCU actions · hunting P User Discovery With Env Vars PowerShell Script Block ESCU actions · hunting P Windows Common Abused Cmd Shell Risk Behavior ESCU actions · alerting P Windows System Discovery Using ldap Nslookup ESCU actions · hunting P Windows System Discovery Using Qwinsta ESCU actions · hunting P Windows System Remote Discovery With Query ESCU actions · hunting P Windows System User Discovery Via Quser ESCU actions · hunting P Windows System User Privilege Discovery ESCU actions · hunting P Windows WinPEAS PowerShell Script Execution ESCU actions · alerting P [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) Bespoke exploit · alerting DSΣPCS [LLM] Python process spawning shell with TeamPCP recon chain (hostname; whoami; uname; ip addr fallback) Bespoke actions · alerting DSΣPDDCS [LLM] Package-manager install hook spawning host-recon curl/wget exfil (pre.sh pattern) Bespoke install · alerting DSΣPDDCS

Articles citing this technique (4)