Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1087

T1087Account Discovery

T1087 — Account Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 11 detection use cases covering it and 4 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
11Use cases
4Articles
4Sub-techniques
1Tactic

Sub-techniques (4)

Use cases covering this technique (11)

Enumerate Users Local Group Using Telegram ESCU actions · alerting P Windows Account Discovery for Sam Account Name ESCU actions · hunting P Windows Account Discovery With NetUser PreauthNotRequire ESCU actions · hunting P Windows Special Privileged Logon On Multiple Hosts ESCU actions · alerting P Splunk Account Discovery Drilldown Dashboard Disclosure ESCU actions · alerting P Splunk Image File Disclosure via PDF Export in Classic Dashboard ESCU actions · hunting P Splunk Information Disclosure on Account Login ESCU actions · hunting P Splunk SG Information Disclosure for Low Privs User ESCU actions · hunting P [LLM] new-api CVE-2026-64859: admin user-list/detail API access token disclosure scoping Bespoke exploit · hunting SΣP [LLM] SharePoint CVE-2026-55040 chain: metadata recon then post-bypass API calls from one external IP Bespoke actions · alerting SP [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin Bespoke install · alerting DSΣP

Articles citing this technique (4)