MITRE ATT&CK Technique
T1087.002Domain Account
- First Reported
- Jul 14, 2025
- Latest Reported
- Oct 1, 2026
Official Description
Adversaries may attempt to get a listing of domain accounts. This information can help adversaries determine which domain accounts exist to aid in follow-on behavior such as targeting specific accounts which possess particular privileges.
Commands such as <code>net user /domain</code> and <code>net group /domain</code> of the [Net](https://attack.mitre.org/software/S0039) utility, <code>dscacheutil -q group</code> on macOS, and <code>ldapsearch</code> on Linux can list domain users and groups. [PowerShell](https://attack.mitre.org/techniques/T1059/001) cmdlets including <code>Get-ADUser</code> and <code>Get-ADGroupMember</code> may enumerate members of Active Directory groups.(Citation: CrowdStrike StellarParticle January 2022)
Commands such as <code>net user /domain</code> and <code>net group /domain</code> of the [Net](https://attack.mitre.org/software/S0039) utility, <code>dscacheutil -q group</code> on macOS, and <code>ldapsearch</code> on Linux can list domain users and groups. [PowerShell](https://attack.mitre.org/techniques/T1059/001) cmdlets including <code>Get-ADUser</code> and <code>Get-ADGroupMember</code> may enumerate members of Active Directory groups.(Citation: CrowdStrike StellarParticle January 2022)
- Tactics
- Discovery
- Platforms
- Linux, macOS, Windows
- Parent Technique
- T1087 · Account Discovery
- MITRE Version
- 1.2
- Last Modified
- May 12, 2026
Reported Context (7)
- The attackers ran net user /domain during reconnaissance. Warlock Ransomware Group Hits Water and Telecom Operators, Continues Exploiting SharePoint
- The agent enumerated Active Directory accounts and used Bloodhound Python collector for extensive account reconnaissance. Darktrace Tests Show AI Agents Hacking Simulated Corporate Networks to Cheat
- On domain-joined hosts, Starland RAT executes net user {USERNAME} /dom to obtain domain account information. UAT-11795 Uses Starland RAT and Custom WLDR C2 Implant in Financially Motivated Campaign
- The threat actor enumerated domain user accounts with net commands and Get-ADUser. Bing SEO Poisoning Led to BumbleBee, AdaptixC2 and Akira Ransomware Intrusions
- AdFind and net user commands were used to enumerate domain users. Lunar Spider Intrusion Used Tax-Themed JavaScript to Maintain Access for Nearly Two Months
CVE (6)
Malware (18)
People (15)
Threat Actors (13)
MITRE ATT&CK (87)
Vendors (11)
Products (33)
Tools (39)
Industries (4)
Countries (17)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.