Techniques › T1589 › T1589.003
T1589.003 Employee Names
reconnaissance — PRE · attack.mitre.org · JSON
1
MITRE detection strategy
1
analytics
0
Sigma rules tagged attack.t1589.003
0
KEV CVEs mapped here
<p>Adversaries may gather employee names that can be used during targeting. Employee names be used to derive email addresses as well as to help guide other reconnaissance efforts and/or craft more-believable lures.</p><p>Adversaries may easily gather employee names, since they may be readily available and exposed via online or other accessible data sets (ex: Social Media or Search Victim-Owned Websites). Gathering this information may reveal opportunities for other forms of reconnaissance (ex: Search Open Websites/Domains or Phishing for Information), establishing operational resources (ex: Compromise Accounts), and/or initial access (ex: Phishing or Valid Accounts).</p>
KEV CVEs mapped to this technique · CTID Mappings Explorer
None. No KEV entry in the public mapping names this technique. Given that 74.7% of KEV has no mapping at all, this says more about the mapping than about the technique.
Detection strategy · ATT&CK Enterprise v19.2
- DET0857 Detection of Employee Names v1.0
AN1989 PREMuch of this activity may have a very high occurrence and associated false positive rate, as well as potentially taking place outside the visibility of the target organization, making detection difficult for defenders. Detection efforts may be focused on related stages of the adversary lifecycle, such as during Initial Access.
Sigma rules · SigmaHQ da9bb07d64, tag attack.t1589.003
No Sigma rule carries this tag. MITRE publishes a detection strategy above, so the behaviour is specified; what is missing is public detection content.
Rules tagged at the parent level (attack.t1589) 2
These target the parent technique, not this sub-technique specifically. Listed for completeness, not counted as coverage.
Author: Mark Morowczynski '@markmorow', Gloria Lee, '@gleeiamglo'
· 2023-09-03 · logsource: product=azure service=riskdetection · 19128e5e-4743-48dc-bd97-52e5775af817
Indicates that the user's valid credentials have been leaked.
Author: Florian Roth (Nextron Systems)
· 2017-08-24 (modified 2021-11-27) · logsource: product=linux service=sshd · 4c9d903d-4939-4094-ade0-3cb748f4d7da
Detects exploitation attempt using public exploit code for CVE-2018-15473