Test your SOC · about a minute

Can your SOC see who is asking who lives here?

One real attacker move, a safe way to run it on a machine you own, and the detection that closes the gap — in that order, so you leave with better coverage than you arrived with.

technique T1087 · Account Discoveryseen in Scattered Spiderwhere any Windows box

What this is about

Can your SOC see an attacker mapping your accounts?

The first thing a hands-on intruder does after landing is ask the machine who lives here. Not with malware — with the same commands your own admins use. net user lists the local accounts, whoami /all reads back exactly what the current token can do. It is quiet, it is built in, and it is how an attacker decides which account to steal next.

The detection does not try to ban these tools — your admins need them. It watches for the pattern: the account-enumeration utilities running, so that when they run at 3am from a process that has no business enumerating anything, someone gets to look.

The detection watches one thing: a built-in tool listing the local accounts and the current user's privileges.

This is not hypothetical

The crew tracked as Scattered Spider is documented doing exactly this. They get in through a help-desk or a phished token, and before they move they enumerate — local accounts, group membership, what the current user is allowed to do — because that map is what turns one foothold into domain-wide access.

No exploit, no custom tooling: commands that ship with every copy of Windows, run by a normal-looking user. The same lines you are about to run yourself — the only question is whether your SOC says a word.

The actor above is named in MITRE ATT&CK’s own Procedure Examples for this technique; the link is where you can read it. Nothing on this page discloses a move an attacker does not already have — it just makes sure the defender has it too.

Built-in, every time

net and whoami ship with Windows. There is no binary to flag, so the signal is the behaviour, not the file.

Any account can do it

Reading the local account list and your own privileges needs no admin rights. It is reconnaissance, and it is invisible unless you watch for it.

It picks the next target

The account map is how an intruder chooses which credential to steal. Catch the mapping and you catch them before the theft.

The test

Run the real thing. Safely. On a box you own.

Run the same enumeration an intruder runs, then open your own alerts.

01

List the local accounts

Run net user — the built-in that dumps every local account on the box.

02

Read your own privileges

Run whoami /all — exactly what an attacker reads to learn what this token can do. This is the moment your SOC should notice.

03

Check your alerts

Open your SOC or EDR. Did account enumeration fire — or did the reconnaissance pass unseen?

test-your-soc-account-discovery.ps1 · PowerShell · a machine you own
# test-your-soc-account-discovery.ps1 — run on a machine you own.
# Safe: these are read-only lookups. Nothing is changed, nothing to undo.
# STEP 1 - list the local accounts, the way an intruder maps who lives here.
net user
# STEP 2 - read back exactly what the current account is allowed to do.
whoami /all
# STEP 3 - open your SOC / EDR. Did account enumeration alert?

Every line is a read-only lookup — it lists accounts and prints your own privileges. Nothing is created, changed or deleted, so there is nothing to undo and no admin rights are needed.

Reading the result — honestly

Something fired

Your tooling watches account-enumeration utilities

Good — you would see an intruder drawing the same map, in the minutes before they act on it. On to the next one.

Silence

The enumeration went unseen — now you know

Not a verdict on your team; a specific, fixable gap you just found in a minute. The detection below is exactly what to hand them to close it.

Straight with you: we never see your alerts — you’re the judge, which is also why we never touch your data. And a lab isn’t production; a test box often logs differently than the real fleet. "It fired" means your EDR flagged net/whoami account enumeration — note that a single lookup can be ordinary admin activity, so a good rule watches for it running from an unexpected parent, which is the harder and more valuable catch. Treat a pass as a reason to go check prod, not a finish line.

How to catch it

Missed it? Here’s the fix — take it straight to your SOC.

The logic is public and every major SIEM already supports it. Here it is in Sigma, the open, vendor-neutral format your team can translate into whatever you run.

proc_creation_win_susp_local_system_owner_account_discovery.yml
title: Local Accounts Discovery
id: 502b42de-4306-40b4-9596-6f590c81f073
status: test
related:
    - id: e28a5a99-da44-436d-b7a0-2afc20a5f413 # Whoami Utility Execution
      type: obsolete
description: Local accounts, System Owner/User discovery using operating systems utilities
references:
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1033/T1033.md
author: Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community
date: 2019-10-21
modified: 2025-10-20
tags:
    - attack.discovery
    - attack.t1033
    - attack.t1087.001
logsource:
    category: process_creation
    product: windows
detection:
    selection_other_img:
        - Image|endswith:
              - '\whoami.exe'
              - '\quser.exe'
              - '\qwinsta.exe'
        - OriginalFileName:
              - 'whoami.exe'
              - 'quser.exe'
              - 'qwinsta.exe'
    selection_other_wmi:
        Image|endswith: '\wmic.exe'
        CommandLine|contains|all:
            - 'useraccount'
            - 'get'
    selection_other_cmdkey:
        Image|endswith: '\cmdkey.exe'
        CommandLine|contains: ' /l'
    selection_cmd:
        Image|endswith: '\cmd.exe'
        CommandLine|contains|all:
            - ' /c'
            - 'dir '
            - '\Users\'
    filter_cmd:
        CommandLine|contains: ' rmdir ' # don't match on 'dir'   "C:\Windows\System32\cmd.exe" /q /c rmdir /s /q "C:\Users\XX\AppData\Local\Microsoft\OneDrive\19.232.1124.0005"
    selection_net:
        Image|endswith:
            - '\net.exe'
            - '\net1.exe'
        CommandLine|contains: 'user'
    filter_net:
        CommandLine|contains:
            - '/domain'       # local account discovery only
            - '/add'          # discovery only
            - '/delete'       # discovery only
            - '/active'       # discovery only
            - '/expires'      # discovery only
            - '/passwordreq'  # discovery only
            - '/scriptpath'   # discovery only
            - '/times'        # discovery only
            - '/workstations' # discovery only
    condition: (selection_cmd and not filter_cmd) or (selection_net and not filter_net) or 1 of selection_other_*
falsepositives:
    - Legitimate administrator or user enumerates local users for legitimate reason
level: low
simulation:
    - type: atomic-red-team
      name: WMI Reconnaissance Users
      technique: T1047
      atomic_guid: c107778c-dcf5-47c5-af2e-1d058a3df3ea
regression_tests_path: regression_data/rules/windows/process_creation/proc_creation_win_susp_local_system_owner_account_discovery/info.yml

Local Accounts Discovery · SigmaHQ rule 502b42de-4306-40b4-9596-6f590c81f073

Author Timur Zinniatullin, Daniil Yugoslavskiy, oscd.community · quoted in full and unmodified under the Detection Rule License 1.1 (DRL 1.1)

https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_susp_local_system_owner_account_discovery.yml

Retrieved 2026-09-11 · file sha256 ddb20029d804c7a434cc6600659aaac2b646b67cd150470e9b1ef4be47c16e06

If your test came back silent, that rule is the whole fix. Drop it into your SIEM, or send your provider this page — “we ran this, nothing fired, here’s the detection.” Either way your coverage is better tonight than it was this morning. That’s the point.

A new one every week

This is technique 02 of many.

Each one is a real attacker move, a safe way to try it, and the detection to close the gap. Run them over a few weeks and you’ll learn more about your real coverage than any dashboard has told you.

Curious how a system catches all of these at once, out of the box? That’s what we build — meet Mobula →

Credit & sources

The technique and the incident are documented by MITRE ATT&CK (T1087) and the sources linked above. The detection is expressed in Sigma, the open detection format maintained by the SigmaHQ community, so any team can use it freely; its author is credited above under DRL 1.1.

We show you public attacker tradecraft and public detection logic, and hand you both. Nothing here reveals anything an attacker doesn’t already have — it just makes sure the defender has it too.

CYRAY · MOBULA — SECURITY OPERATIONS, ORCHESTRATED BY AI