atomic-red-team/Windows/Discovery/System Owner-User Discovery.md

32 lines
357 B
Markdown
Raw Permalink Normal View History

2017-10-11 17:35:17 +00:00
## System Owner/User Discovery
MITRE ATT&CK Technique: [T1018](https://attack.mitre.org/wiki/Technique/T1018)
### cmd.exe
"cmd.exe" /C whoami
### wmic.exe
wmic useraccount get /ALL
### quser
Remote:
2017-10-11 17:35:17 +00:00
quser /SERVER:"<computername>"
Local:
quser
2017-10-11 17:35:17 +00:00
### qwinsta
Remote:
2017-10-11 17:35:17 +00:00
qwinsta.exe" /server:<computername>
Local:
qwinsta.exe