kevmap

TechniquesT1087 › AN1612

AN1612 Analytic 1612

Windows · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detection of processes performing local or domain account enumeration by invoking account directory queries or security APIs followed by structured output of account lists. The defender observes command execution or API invocation patterns that retrieve account information and produce enumeration artifacts shortly afterward.</p>
Detects
T1087 Account Discovery
Part of
DET0587 Enumeration of User or Account Information Across Platforms

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
WinEventLog:SysmonEventCode=1DC0032 Process Creation
WinEventLog:SecurityEventCode=4688DC0032 Process Creation
WinEventLog:SecurityEventCode=4798, 4799DC0099 Group Enumeration

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
CommandLinePatternMatch variations in enumeration commands like 'net user', 'Get-ADUser', 'dsquery'.
TimeWindowShort burst of account enumeration commands may indicate automation.
UserContextRestrict to non-admin accounts or unexpected users executing enumeration commands.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2021-44515Zoho Desktop CentralMapped
CVE-2022-41082Microsoft Exchange ServerMapped
CVE-2023-27532Veeam Backup & ReplicationMapped
CVE-2024-13159Ivanti Endpoint Manager (EPM)Mapped
CVE-2024-13160Ivanti Endpoint Manager (EPM)Mapped
CVE-2024-13161Ivanti Endpoint Manager (EPM)Mapped