kevmap

TechniquesT1069 › T1069.001

T1069.001 Local Groups

discovery — Linux, macOS, Windows · attack.mitre.org · JSON

1
MITRE detection strategy
3
analytics
16
Sigma rules tagged attack.t1069.001
0
KEV CVEs mapped here
<p>Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.</p><p>Commands such as <code>net localgroup</code> of the Net utility, <code>dscl . -list /Groups</code> on macOS, and <code>groups</code> on Linux can list local groups.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1069.001

Author: Nasreddine Bencherchali (Nextron Systems) · 2023-01-02 (modified 2025-12-10) · logsource: product=windows category=process_creation · 02030f2f-6199-49ec-b258-ea71b07e03dc
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: C.J. May · 2022-08-09 (modified 2026-02-19) · logsource: product=windows category=file_event · 02773bed-83bf-469f-b7ff-e676e7d78bab
Detects default file names outputted by the BloodHound collection tool SharpHound
Author: frack113 · 2021-12-12 (modified 2023-02-14) · logsource: product=windows category=process_creation · 164eda96-11b2-430b-85ff-6a265c15bf32
Detects the execution of "wmic" with the "group" flag. Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.
Techniques: T1069.001
Author: Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements) · 2019-01-16 (modified 2022-07-11) · logsource: product=windows category=process_creation · 183e7ea8-ac4b-4c23-9aec-b3dac4e401ac
Detects execution of "Net.EXE".
Author: Ömer Günal, Alejandro Ortuno, oscd.community · 2020-10-11 (modified 2025-06-04) · logsource: product=linux category=process_creation · 676381a6-15ca-4d73-a9c8-6a22e970b90d
Detects enumeration of local system groups. Adversaries may attempt to find local system groups and permission settings
Techniques: T1069.001
Author: frack113 · 2021-12-15 (modified 2022-12-02) · logsource: product=windows category=ps_module · 6942bd25-5970-40ab-af49-944247103358
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
Techniques: T1069.001
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-01-20 (modified 2025-12-10) · logsource: product=windows category=ps_module · 7d0d0329-0ef1-4e84-a9f5-49500f9d7c6c
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: frack113 · 2021-12-15 (modified 2023-01-20) · logsource: product=windows category=ps_module · 815bfc17-7fc6-4908-a55e-2f37b98cedb4
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
Techniques: T1069.001
Author: frack113 · 2021-12-15 (modified 2022-12-25) · logsource: product=windows category=ps_script · 88f0884b-331d-403d-a3a1-b668cf035603
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
Techniques: T1069.001
Author: Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer · 2017-03-05 (modified 2025-12-10) · logsource: product=windows category=ps_script · 89819aa4-bbd6-46bc-88ec-c7f7fe30efa6
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Ömer Günal, Alejandro Ortuno, oscd.community · 2020-10-11 (modified 2022-11-27) · logsource: product=macos category=process_creation · 89bb1f97-c7b9-40e8-b52b-7d6afbd67276
Detects enumeration of local system groups
Techniques: T1069.001
Author: frack113 · 2021-12-15 (modified 2022-12-25) · logsource: product=windows category=ps_script · 95f0643a-ed40-467c-806b-aac9542ec5ab
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of interest for Lateral Movement. Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
Techniques: T1069.001
Author: Teymur Kheirkhabarov (idea), Mangatas Tondang, oscd.community, Nasreddine Bencherchali (Nextron Systems) · 2020-10-13 (modified 2026-06-29) · logsource: product=windows category=process_creation · c625d754-6a3d-4f65-9c9a-536aea960d37
Detects the usage of the "Accesschk" utility, an access and privilege audit tool developed by SysInternal and often being abused by attacker to verify process privileges
Techniques: T1069.001
Author: frack113 · 2021-12-12 (modified 2025-08-22) · logsource: product=windows category=ps_module · cef24b90-dddc-4ae1-a09a-8764872f69fc
Detects the use of PowerShell modules and cmdlets to gather local group information. Adversaries may use local system permission groups to determine which groups exist and which users belong to a particular group such as the local administrators group.
Techniques: T1069.001
Author: Florian Roth (Nextron Systems) · 2019-12-20 (modified 2023-02-04) · logsource: product=windows category=process_creation · f376c8a7-a2d0-4ddc-aa0c-16c17236d962
Detects command line parameters used by Bloodhound and Sharphound hack tools
Author: frack113 · 2021-12-12 (modified 2025-08-22) · logsource: product=windows category=ps_script · fa6a5a45-3ee2-4529-aa14-ee5edc9e29cb
Detects the use of PowerShell modules and cmdlets to gather local group information. Adversaries may use local system permission groups to determine which groups exist and which users belong to a particular group such as the local administrators group.
Techniques: T1069.001

Rules tagged at the parent level (attack.t1069) 3

These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.

Author: Nasreddine Bencherchali (Nextron Systems) · 2023-01-02 (modified 2025-12-10) · logsource: product=windows category=process_creation · 02030f2f-6199-49ec-b258-ea71b07e03dc
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Nasreddine Bencherchali (Nextron Systems) · 2023-01-20 (modified 2025-12-10) · logsource: product=windows category=ps_module · 7d0d0329-0ef1-4e84-a9f5-49500f9d7c6c
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer · 2017-03-05 (modified 2025-12-10) · logsource: product=windows category=ps_script · 89819aa4-bbd6-46bc-88ec-c7f7fe30efa6
Detects Commandlet names from well-known PowerShell exploitation frameworks