40
Groups Using This
1
Tactics
4
Platforms
27
Prevalence Rank
Description

Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using OS Credential Dumping. The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from System Owner/User Discovery during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Various utilities and commands may acquire this information, including whoami. In macOS and Linux, the currently logged in user can be identified with w and who. On macOS the dscl . list /Users | grep -v '_' command can also be used to enumerate user accounts. Environment variables, such as %USERNAME% and $USER, may also be used to access this information. On network devices, Network Device CLI commands such as `show users` and `show ssh` can be used to display users currently logged into the device.

View MITRE record โ†—

Platforms
LinuxmacOSNetwork DevicesWindows
Groups Using T1033 (40)
G0094
Kimsuky
๐Ÿ‡ท๐Ÿ‡บ Russia130 techniques19 software
G0032
Lazarus Group
๐Ÿ‡ฐ๐Ÿ‡ต North Korea93 techniques26 software
G0096
APT41
๐Ÿ‡จ๐Ÿ‡ณ China82 techniques32 software
G1017
Volt Typhoon
๐Ÿ‡จ๐Ÿ‡ณ China81 techniques17 software
G0034
Sandworm Team
๐Ÿ‡ท๐Ÿ‡บ Russia79 techniques27 software
G0050
APT32
๐Ÿ‡ป๐Ÿ‡ณ Vietnam78 techniques15 software
G0059
Magic Hound
๐Ÿ‡ฎ๐Ÿ‡ท Iran78 techniques13 software
G0049
OilRig
๐Ÿ‡ฎ๐Ÿ‡ท Iran76 techniques30 software
G0047
Gamaredon Group
๐Ÿ‡ท๐Ÿ‡บ Russia70 techniques6 software
G0069
MuddyWater
๐Ÿ‡ฎ๐Ÿ‡ท Iran68 techniques21 software
G0046
FIN7
67 techniques19 software
G0102
Wizard Spider
๐Ÿ‡ท๐Ÿ‡บ Russia64 techniques22 software
G0114
Chimera
๐Ÿ‡จ๐Ÿ‡ณ China59 techniques6 software
G0027
Threat Group-3390
๐Ÿ‡จ๐Ÿ‡ณ China57 techniques24 software
G1051
Medusa Group
57 techniques5 software
G0082
APT38
๐Ÿ‡ฐ๐Ÿ‡ต North Korea56 techniques6 software
G0035
Dragonfly
๐Ÿ‡ท๐Ÿ‡บ Russia56 techniques10 software
G0087
APT39
๐Ÿ‡ฎ๐Ÿ‡ท Iran53 techniques11 software
G0004
Ke3chang
๐Ÿ‡จ๐Ÿ‡ณ China46 techniques11 software
G1006
Earth Lusca
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques9 software
G0022
APT3
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G0125
HAFNIUM
๐Ÿ‡จ๐Ÿ‡ณ China44 techniques6 software
G1054
MirrorFace
๐Ÿ‡จ๐Ÿ‡ณ China43 techniques16 software
G0040
Patchwork
๐Ÿ‡จ๐Ÿ‡ณ China41 techniques8 software
G0081
Tropic Trooper
40 techniques6 software
G0061
FIN8
36 techniques11 software
G1001
HEXANE
36 techniques12 software
G0143
Aquatic Panda
๐Ÿ‡จ๐Ÿ‡ณ China35 techniques6 software
G1046
Storm-1811
31 techniques7 software
G0093
GALLIUM
๐Ÿ‡ท๐Ÿ‡บ Russia31 techniques16 software
G1036
Moonstone Sleet
๐Ÿ‡ฐ๐Ÿ‡ต North Korea30 techniques1 software
G0121
Sidewinder
๐Ÿ‡จ๐Ÿ‡ณ China30 techniques1 software
G0128
ZIRCONIUM
๐Ÿ‡จ๐Ÿ‡ณ China29 techniques0 software
G0067
APT37
๐Ÿ‡ท๐Ÿ‡บ Russia29 techniques13 software
G1014
LuminousMoth
๐Ÿ‡จ๐Ÿ‡ณ China28 techniques2 software
G1035
Winter Vivern
๐Ÿ‡ท๐Ÿ‡บ Russia27 techniques0 software
G0073
APT19
๐Ÿ‡จ๐Ÿ‡ณ China21 techniques2 software
G0112
Windshift
19 techniques1 software
G0038
Stealth Falcon
16 techniques0 software
G0051
FIN10
11 techniques1 software
โ†‘