Skip to content
← LibraryTechnique entry
T1087Discovery

Account Discovery

Enumerate local or domain accounts.

§ Where this technique fits

T1087 is catalogued under the Discovery tactic of the offensive-security kill-chain. It appears in 19 approved dossiers in the registry, typically at step 2.8 on average.

Authoritative reference: attack.mitre.org/techniques/T1087/.

§ Dossiers chaining this technique

§ What commonly comes next

  1. 01
    Exfiltration Over C2 Channel
    T1041 · Exfiltration
    seen 2×
  2. 02
    Network Sniffing
    T1040 · Credential Access
    seen 2×
  3. 03
    ADB Backup Extraction
    MOB-BACKUP-EXTRACT · Collection
    seen 1×
  4. 04
    AWS iam:PassRole Chain
    C-AWS-IAM-PASSROLE · Privilege Escalation
    seen 1×
  5. 05
    AWS sts:AssumeRole Chain
    C-AWS-ASSUMEROLE-CHAIN · Lateral Movement
    seen 1×
  6. 06
    Azure RBAC Owner Assignment
    C-AZ-RBAC-OWNER · Privilege Escalation
    seen 1×
  7. 07
    DICOM C-STORE Unauth Access
    HC-DICOM-CSTORE · Collection
    seen 1×
  8. 08
    Dylib Hijack
    MAC-DYLIB-HIJACK · Privilege Escalation
    seen 1×