Techniques › T1069 › T1069.001
T1069.001 Local Groups
discovery — Linux, macOS, Windows · attack.mitre.org · JSON
1
MITRE detection strategy
3
analytics
16
Sigma rules tagged attack.t1069.001
0
KEV CVEs mapped here
<p>Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.</p><p>Commands such as <code>net localgroup</code> of the Net utility, <code>dscl . -list /Groups</code> on macOS, and <code>groups</code> on Linux can list local groups.</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0114 Behavioral Detection of Local Group Enumeration Across OS Platforms v1.0
AN0317 WindowsDetects attempts to enumerate local groups via Net.exe, PowerShell, or native API calls that precede lateral movement or privilege abuse.Tunable:
TimeWindowUserContextAN0318 LinuxDetects enumeration of local groups using common binaries (groups, getent, cat /etc/group) or scripting with suspicious lineage.Tunable:ProcessNameParentProcessAN0319 macOSDetects use of dscl or id/group commands to enumerate local system groups, often by post-exploitation tools or persistence checks.Tunable:CommandLineContainsInteractiveSession
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1069.001
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-01-02 (modified 2025-12-10) · logsource: product=windows category=process_creation · 02030f2f-6199-49ec-b258-ea71b07e03dc
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: C.J. May
· 2022-08-09 (modified 2026-02-19) · logsource: product=windows category=file_event · 02773bed-83bf-469f-b7ff-e676e7d78bab
Detects default file names outputted by the BloodHound collection tool SharpHound
Author: frack113
· 2021-12-12 (modified 2023-02-14) · logsource: product=windows category=process_creation · 164eda96-11b2-430b-85ff-6a265c15bf32
Detects the execution of "wmic" with the "group" flag.
Adversaries may attempt to find local system groups and permission settings.
The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group.
Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group.
Author: Michael Haag, Mark Woan (improvements), James Pemberton / @4A616D6573 / oscd.community (improvements)
· 2019-01-16 (modified 2022-07-11) · logsource: product=windows category=process_creation · 183e7ea8-ac4b-4c23-9aec-b3dac4e401ac
Detects execution of "Net.EXE".
Author: Ömer Günal, Alejandro Ortuno, oscd.community
· 2020-10-11 (modified 2025-06-04) · logsource: product=linux category=process_creation · 676381a6-15ca-4d73-a9c8-6a22e970b90d
Detects enumeration of local system groups. Adversaries may attempt to find local system groups and permission settings
Author: frack113
· 2021-12-15 (modified 2022-12-02) · logsource: product=windows category=ps_module · 6942bd25-5970-40ab-af49-944247103358
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and
to identify potential systems of interest for Lateral Movement.
Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-01-20 (modified 2025-12-10) · logsource: product=windows category=ps_module · 7d0d0329-0ef1-4e84-a9f5-49500f9d7c6c
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: frack113
· 2021-12-15 (modified 2023-01-20) · logsource: product=windows category=ps_module · 815bfc17-7fc6-4908-a55e-2f37b98cedb4
Adversaries may attempt to find domain-level groups and permission settings.
The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group.
Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
Author: frack113
· 2021-12-15 (modified 2022-12-25) · logsource: product=windows category=ps_script · 88f0884b-331d-403d-a3a1-b668cf035603
Adversaries may attempt to find domain-level groups and permission settings.
The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group.
Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
Author: Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer
· 2017-03-05 (modified 2025-12-10) · logsource: product=windows category=ps_script · 89819aa4-bbd6-46bc-88ec-c7f7fe30efa6
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Ömer Günal, Alejandro Ortuno, oscd.community
· 2020-10-11 (modified 2022-11-27) · logsource: product=macos category=process_creation · 89bb1f97-c7b9-40e8-b52b-7d6afbd67276
Detects enumeration of local system groups
Author: frack113
· 2021-12-15 (modified 2022-12-25) · logsource: product=windows category=ps_script · 95f0643a-ed40-467c-806b-aac9542ec5ab
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as
a precursor for Collection and to identify potential systems of interest for Lateral Movement.
Networks often contain shared network drives and folders that enable users to access file directories on various systems across a network.
Author: Teymur Kheirkhabarov (idea), Mangatas Tondang, oscd.community, Nasreddine Bencherchali (Nextron Systems)
· 2020-10-13 (modified 2026-06-29) · logsource: product=windows category=process_creation · c625d754-6a3d-4f65-9c9a-536aea960d37
Detects the usage of the "Accesschk" utility, an access and privilege audit tool developed by SysInternal and often being abused by attacker to verify process privileges
Author: frack113
· 2021-12-12 (modified 2025-08-22) · logsource: product=windows category=ps_module · cef24b90-dddc-4ae1-a09a-8764872f69fc
Detects the use of PowerShell modules and cmdlets to gather local group information.
Adversaries may use local system permission groups to determine which groups exist and which users belong to a particular group such as the local administrators group.
Author: Florian Roth (Nextron Systems)
· 2019-12-20 (modified 2023-02-04) · logsource: product=windows category=process_creation · f376c8a7-a2d0-4ddc-aa0c-16c17236d962
Detects command line parameters used by Bloodhound and Sharphound hack tools
Author: frack113
· 2021-12-12 (modified 2025-08-22) · logsource: product=windows category=ps_script · fa6a5a45-3ee2-4529-aa14-ee5edc9e29cb
Detects the use of PowerShell modules and cmdlets to gather local group information.
Adversaries may use local system permission groups to determine which groups exist and which users belong to a particular group such as the local administrators group.
Rules tagged at the parent level (attack.t1069) 3
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-01-02 (modified 2025-12-10) · logsource: product=windows category=process_creation · 02030f2f-6199-49ec-b258-ea71b07e03dc
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Nasreddine Bencherchali (Nextron Systems)
· 2023-01-20 (modified 2025-12-10) · logsource: product=windows category=ps_module · 7d0d0329-0ef1-4e84-a9f5-49500f9d7c6c
Detects Commandlet names from well-known PowerShell exploitation frameworks
Author: Sean Metcalf, Florian Roth, Bartlomiej Czyz @bczyz1, oscd.community, Nasreddine Bencherchali, Tim Shelton, Mustafa Kaan Demir, Georg Lauenstein, Max Altgelt, Tobias Michalski, Austin Songer
· 2017-03-05 (modified 2025-12-10) · logsource: product=windows category=ps_script · 89819aa4-bbd6-46bc-88ec-c7f7fe30efa6
Detects Commandlet names from well-known PowerShell exploitation frameworks