Compliance Node Overview
MITRE ATT&CK T1087.001 (Local Account) is an Enterprise Discovery sub-technique of T1087 (Account Discovery). Adversaries may attempt to get a listing of local system accounts. This information can help adversaries determine which local accounts exist on a system to aid in follow-on behavior. Commands such as net user and net localgroup of the Net utility and id and groups on macOS and Linux can list local users and groups. On Linux, local users can also be enumerated through the use of the /etc/passwd file. On macOS the dscl . list /Users command can be used to enumerate local accounts. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, CM-06, CM-07, SI-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1087/001/
SHA-256 integrity: 12362b9ac84d9f652da55b525a06e133ebd36af446358b560bbacb252404de00
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1087.001: Local Account (https://attack.mitre.org/techniques/T1087/001/)
- MITRE ATT&CK Tactic TA0007: Discovery (https://attack.mitre.org/tactics/TA0007/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.