What MITRE ATT&CK T1087.002: Domain Account (Enterprise Tactic TA0007 - Discovery) requires
MITRE ATT&CK T1087.002 (Domain Account) is an Enterprise Discovery sub-technique of T1087 (Account Discovery). Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges. Commands such as net user /domain and net group /domain of the Net utility, dscacheutil -q group on macOS, and ldapsearch on Linux can list domain users and groups. PowerShell cmdlets including Get-ADUser and Get-ADGroupMember may enumerate members of Active Directory groups. Affected platforms: Linux, macOS, Windows. MITRE-documented mitigations include M1028 Operating System Configuration. The Center for Threat-Informed Defense maps this technique to NIST SP 800-53 Rev 5 controls AC-02, CM-06, CM-07, SI-04.
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1087/002/
SHA-256 integrity: 727f77e8dc7f23415039490cbf9c31e681ba3fccd0f0ced9bcf233330d2f910e
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1087.002: Domain Account (https://attack.mitre.org/techniques/T1087/002/)
- MITRE ATT&CK Tactic TA0007: Discovery (https://attack.mitre.org/tactics/TA0007/)
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.