For the complete documentation index, see llms.txt. This page is also available as Markdown.

Local user enumeration via SAMR

Synopsis

Field
Value

Activation Period

14 Days

Training Period

30 Days

Test Period

N/A (single event)

Deduplication Period

1 Day

Required Data

XDR Agent with eXtended Threat Hunting (XTH)

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Account Discovery: Local Account (T1087.001)

Severity

Informational

Description

A user enumerated local users via SAMR.

Attacker's Goals

An adversary may leverage local user discovery to identify privileged users and escalate privileges.

Investigative actions

  • Determine the user, hostname, and process that performed the user enumeration.

  • Inspect process, command-line arguments or scripts used.

  • Check for any privilege escalation or lateral movement attempts from the source system.

  • Check if the tool used to enumerate the local users is a known or an approved tool.

  • Review the logs for suspicious activity from the same host or user.

Variations

Local user enumeration via SAMR on an internet facing server

Synopsis

Field
Value

ATT&CK Tactic

Discovery (TA0007)

ATT&CK Technique

Account Discovery: Local Account (T1087.001)

Severity

Low

Description

A user enumerated local users via SAMR.

Attacker's Goals

An adversary may leverage local user discovery to identify privileged users and escalate privileges.

Investigative actions

  • Determine the user, hostname, and process that performed the user enumeration.

  • Inspect process, command-line arguments or scripts used.

  • Check for any privilege escalation or lateral movement attempts from the source system.

  • Check if the tool used to enumerate the local users is a known or an approved tool.

  • Review the logs for suspicious activity from the same host or user.

Was this helpful?