Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Discovery/ T1087

T1087Account Discovery

T1087 — Account Discovery is a MITRE ATT&CK technique in the Discovery tactic. Clankerusecase tracks 8 detection use cases covering it and 6 threat-intel articles citing it.

Discovery
View on the matrix → Filter Detection Library MITRE official spec ↗
8Use cases
6Articles
4Sub-techniques
1Tactic

Sub-techniques (4)

Use cases covering this technique (8)

Enumerate Users Local Group Using Telegram ESCU actions · alerting P Windows Account Discovery for Sam Account Name ESCU actions · hunting P Windows Account Discovery With NetUser PreauthNotRequire ESCU actions · hunting P Windows Special Privileged Logon On Multiple Hosts ESCU actions · alerting P [LLM] Bulk Matrix profile/room-member enumeration against Tchap endpoint Bespoke recon · hunting DSPDDCS [LLM] nebula-mesh CVE-2026-47724 — operator roster + API key metadata enumeration burst Bespoke recon · hunting SPDD [LLM] MCPHub SSE user-segment fan-out — single source spawning sessions under multiple usernames Bespoke recon · alerting SPDD [LLM] MuddyWater SimpleHelp RMM client spawning shell or recon LOLBin Bespoke install · alerting DSΣP

Articles citing this technique (6)