{"id":"T1589","name":"Gather Victim Identity Information","url":"https://attack.mitre.org/techniques/T1589","tactics":["reconnaissance"],"platforms":["PRE"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0841","stix_id":"x-mitre-detection-strategy--b5ec4351-ee04-4beb-a019-b1f6d0e00894","name":"Detection of Gather Victim Identity Information","url":"https://attack.mitre.org/detectionstrategies/DET0841","analytics":[{"id":"AN1973","stix_id":"x-mitre-analytic--dc58724a-18a9-4bb9-a901-f5630963095b","name":"Analytic 1973","description":"Monitor for suspicious network traffic that could be indicative of probing for user information, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.","url":"https://attack.mitre.org/detectionstrategies/DET0841#AN1973","platforms":["PRE"],"log_source_references":[{"name":"Network Traffic","channel":"None","data_component":"DC0085","data_component_name":"Network Traffic Content","log_source_slug":"network-traffic"}],"mutable_elements":[],"live":true,"detection_strategies":["DET0841"],"techniques":["T1589"]}],"live":true,"version":"1.0","techniques":["T1589"]}],"sigma_rules":[{"id":"19128e5e-4743-48dc-bd97-52e5775af817","title":"Azure AD Account Credential Leaked","author":"Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'","status":"test","level":"high","date":"2023-09-03","modified":null,"description":"Indicates that the user's valid credentials have been leaked.","references":["https://learn.microsoft.com/en-us/entra/id-protection/concept-identity-protection-risks#leaked-credentials","https://learn.microsoft.com/en-us/entra/architecture/security-operations-user-accounts#unusual-sign-ins"],"logsource":{"product":"azure","service":"riskdetection"},"tags":["attack.t1589","attack.reconnaissance"],"path":"rules/cloud/azure/identity_protection/azure_identity_protection_leaked_credentials.yml","techniques":["T1589"],"cves":[]},{"id":"4c9d903d-4939-4094-ade0-3cb748f4d7da","title":"SSHD Error Message CVE-2018-15473","author":"Florian Roth (Nextron Systems)","status":"test","level":"medium","date":"2017-08-24","modified":"2021-11-27","description":"Detects exploitation attempt using public exploit code for CVE-2018-15473","references":["https://github.com/Rhynorater/CVE-2018-15473-Exploit"],"logsource":{"product":"linux","service":"sshd"},"tags":["attack.reconnaissance","attack.t1589","cve.2018-15473","detection.emerging-threats"],"path":"rules-emerging-threats/2018/Exploits/CVE-2018-15473/lnx_sshd_exploit_cve_2018_15473.yml","techniques":["T1589"],"cves":["CVE-2018-15473"]}],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}