MITRE ATT&CK Technique
T1069.002Domain Groups
- First Reported
- Sep 8, 2025
- Latest Reported
- Sep 3, 2026
Official Description
Adversaries may attempt to find domain-level groups and permission settings. The knowledge of domain-level permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as domain administrators.
Commands such as <code>net group /domain</code> of the [Net](https://attack.mitre.org/software/S0039) utility, <code>dscacheutil -q group</code> on macOS, and <code>ldapsearch</code> on Linux can list domain-level groups.
Commands such as <code>net group /domain</code> of the [Net](https://attack.mitre.org/software/S0039) utility, <code>dscacheutil -q group</code> on macOS, and <code>ldapsearch</code> on Linux can list domain-level groups.
- Tactics
- Discovery
- Platforms
- Linux, macOS, Windows
- Parent Technique
- T1069 · Permission Groups Discovery
- MITRE Version
- 1.2
- Last Modified
- May 12, 2026
Reported Context (5)
- The attackers ran net.exe group "domain computers" /dom to enumerate members of the domain computers group. Attackers Revive Node.js Abuse to Run Malware and Maintain Persistence
- The threat actor queried domain administrative groups and group memberships. Bing SEO Poisoning Led to BumbleBee, AdaptixC2 and Akira Ransomware Intrusions
- The attacker queried the domain administrator group during the second intrusion after earlier malformed discovery commands. Apache ActiveMQ Exploit Led to LockBit Ransomware Deployment
- The intruder queried Domain Admins and enumerated Active Directory groups. Lunar Spider Intrusion Used Tax-Themed JavaScript to Maintain Access for Nearly Two Months
- The actor ran net group "Domain Admins" /domain. DFIR Report Links Intrusion to Tools Used by Three Ransomware Groups
CVE (2)
Malware (24)
People (16)
Threat Actors (5)
MITRE ATT&CK (71)
Vendors (6)
Products (18)
Tools (32)
Industries (8)
Countries (9)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.