kevmap

TechniquesT1033 › AN0254

AN0254 Analytic 0254

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Adversary launches built-in system tools (e.g., whoami, query user, net user) or scripts that enumerate user account information via local execution or remote API queries (e.g., WMI, PowerShell).</p>
Detects
T1033 System Owner/User Discovery
Part of
DET0093 Behavioral Detection of User Discovery via Local and Remote Enumeration

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:PowerShellEventCode=4103, 4104, 4105, 4106DC0064 Command Execution

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
ParentProcessContextIdentify if enumeration originates from non-interactive shell or system service
TimeWindowTune temporal grouping of enumeration + lateral movement attempts
UserContextFlag unexpected users issuing enumeration commands (e.g., service accounts)

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2023-22518Atlassian Confluence Data Center and ServerMapped
CVE-2024-4577PHP Group PHPMapped