Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1087.001

T1087.001Local Account

T1087.001 — Local Account is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 16 detection use cases covering it and 1 threat-intel article citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
16Use cases
1Articles
0Sub-techniques
1Tactic

Use cases covering this technique (16)

Detect AzureHound Command-Line Arguments ESCU actions · alerting P Detect AzureHound File Modifications ESCU actions · alerting P Detect SharpHound Command-Line Arguments ESCU actions · alerting P Detect SharpHound File Modifications ESCU actions · alerting P Detect SharpHound Usage ESCU actions · alerting P GetLocalUser with PowerShell ESCU actions · hunting P GetLocalUser with PowerShell Script Block ESCU actions · hunting P GetWmiObject User Account with PowerShell ESCU actions · hunting P GetWmiObject User Account with PowerShell Script Block ESCU actions · hunting P Local Account Discovery With Wmic ESCU actions · hunting P Network Traffic to Active Directory Web Services Protocol ESCU actions · hunting P Windows Account Discovery for None Disable User Account ESCU actions · hunting P Windows SOAPHound Binary Execution ESCU actions · alerting P Windows User Discovery Via Net ESCU actions · hunting P Local Account Discovery with Net ESCU actions · hunting P [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) Bespoke exploit · alerting DSΣPCS

Articles citing this technique (1)