Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1069.001

T1069.001Local Groups

T1069.001 — Local Groups is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 16 detection use cases covering it and 1 threat-intel article citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
16Use cases
1Articles
0Sub-techniques
1Tactic

Use cases covering this technique (16)

Detect AzureHound Command-Line Arguments ESCU actions · alerting P Detect AzureHound File Modifications ESCU actions · alerting P Detect SharpHound Command-Line Arguments ESCU actions · alerting P Detect SharpHound File Modifications ESCU actions · alerting P Detect SharpHound Usage ESCU actions · alerting P Get WMIObject Group Discovery ESCU actions · hunting P Get WMIObject Group Discovery with Script Block Logging ESCU actions · hunting P Network Traffic to Active Directory Web Services Protocol ESCU actions · hunting P PowerShell Get LocalGroup Discovery ESCU actions · hunting P Powershell Get LocalGroup Discovery with Script Block Logging ESCU actions · hunting P Windows Admin Permission Discovery ESCU actions · hunting P Windows Group Discovery Via Net ESCU actions · hunting P Windows SOAPHound Binary Execution ESCU actions · alerting P Wmic Group Discovery ESCU actions · hunting P Net Localgroup Discovery ESCU actions · hunting P [LLM] Host reconnaissance sequence spawned from an RMM agent context (BlueDash operator checklist) Bespoke actions · hunting DSΣPDDCS

Articles citing this technique (1)