Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1087

T1087Account Discovery

T1087 — Account Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 9 detection use cases covering it and 2 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
9Use cases
2Articles
4Sub-techniques
1Tactic

Sub-techniques (4)

Use cases covering this technique (9)

Splunk Information Disclosure on Account Login ESCU actions · hunting P Enumerate Users Local Group Using Telegram ESCU actions · alerting P Windows Account Discovery for Sam Account Name ESCU actions · hunting P Windows Account Discovery With NetUser PreauthNotRequire ESCU actions · hunting P Windows Special Privileged Logon On Multiple Hosts ESCU actions · alerting P Splunk Account Discovery Drilldown Dashboard Disclosure ESCU actions · alerting P Splunk Image File Disclosure via PDF Export in Classic Dashboard ESCU actions · hunting P Splunk SG Information Disclosure for Low Privs User ESCU actions · hunting P [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin Bespoke install · alerting DSΣP

Articles citing this technique (2)