Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1033
MITRE ATT&CK Technique

T1033: System Owner/User Discovery

ShareXLinkedInRedditHN

Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using [OS Credential Dumping](https://attack.mitre.org/techniques/T1003). The information may be collected in a number of different ways using other Discovery techniques, because user and username details are prevalent throughout a system and include running process ownership, file/directory ownership, session information, and system logs. Adversaries may use the information from [System Owner/User Discovery](https://attack.mitre.org/techniques/T1033) during automated discovery to shape follow-on behaviors, including whether or not the adversary fully infects the target and/or attempts specific actions. Various utilities and commands may acquire this information, including <code>whoami</code>. In macOS and Linux, the currently logged in user can be identified with <code>w</code> and <code>who</code>. On macOS the <code>dscl . list /Users | grep -v '_'</code> command can also be used to enumerate user accounts. Environment variables, such as <code>%USERNAME%</code> and <code>$USER</code>, may also be used to access this information. On network devices, [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as `show users` and `show ssh` can be used to display users currently logged into the device.(Citation: show_ssh_users_cmd_cisco)(Citation: US-CERT TA18-106A Network Infrastructure Devices 2018)

Tactics
Discovery
Platforms
Linux, macOS, Network Devices, Windows

▪Used by groups (40)

G0004Ke3changG0022APT3G0027Threat Group-3390G0032Lazarus GroupG0034Sandworm TeamG0035DragonflyG0038Stealth FalconG0040PatchworkG0046FIN7G0047Gamaredon GroupG0049OilRigG0050APT32G0051FIN10G0059Magic HoundG0061FIN8G0067APT37G0069MuddyWaterG0073APT19G0081Tropic TrooperG0082APT38G0087APT39G0093GALLIUMG0094KimsukyG0096APT41G0102Wizard SpiderG0112WindshiftG0114ChimeraG0121SidewinderG0125HAFNIUMG0128ZIRCONIUMG0143Aquatic PandaG1001HEXANEG1006Earth LuscaG1014LuminousMothG1017Volt TyphoonG1035Winter VivernG1036Moonstone SleetG1046Storm-1811G1051Medusa GroupG1054MirrorFace

▪Software using this technique (193)

S0013PlugXmalwareS0015IxeshemalwareS0017BISCUITmalwareS0021DerusbimalwareS0024DyremalwareS0058SslMMmalwareS0059WinMMmalwareS0060Sys10malwareS0084Mis-TypemalwareS0085S-TypemalwareS0091EpicmalwareS0092Agent.btzmalwareS0093Backdoor.OldreamalwareS0094Trojan.KaraganymalwareS0098T9000malwareS0113PrikormkamalwareS0115CrimsonmalwareS0125RemsecmalwareS0130Unknown LoggermalwareS0139PowerDukemalwareS0148RTMmalwareS0149MoonWindmalwareS0153RedLeavesmalwareS0155WINDSHIELDmalwareS0161XAgentOSXmalwareS0162KomplexmalwareS0168GazermalwareS0171FelismusmalwareS0172ReavermalwareS0184POWRUNERmalwareS0186DownPapermalwareS0192PupytoolS0201JPINmalwareS0214HAPPYWORKmalwareS0219WINERACKmalwareS0223POWERSTATSmalwareS0228NanHaiShumalwareS0236KwampirsmalwareS0237GravityRATmalwareS0240ROKRATmalwareS0241RATANKBAmalwareS0242SynAckmalwareS0248ytymalwareS0249Gold DragonmalwareS0250KoadictoolS0251ZebrocymalwareS0256MosquitomalwareS0257VERMINmalwareS0258RGDoormalwareS0260InvisiMolemalwareS0262QuasarRATtoolS0265KazuarmalwareS0266TrickBotmalwareS0267FELIXROOTmalwareS0269QUADAGENTmalwareS0270RogueRobinmalwareS0272NDiskMonitormalwareS0275UPPERCUTmalwareS0280MirageFoxmalwareS0284More_eggsmalwareS0331Agent TeslamalwareS0332RemcostoolS0334DarkCometmalwareS0339MicropsiamalwareS0340OctopusmalwareS0344AzorultmalwareS0348Cardinal RATmalwareS0350zwShellmalwareS0351CannonmalwareS0353NOKKImalwareS0354DenismalwareS0356KONNImalwareS0362Linux RabbitmalwareS0363EmpiretoolS0367EmotetmalwareS0374SpeakUpmalwareS0379Revenge RATmalwareS0381FlawedAmmyymalwareS0382ServHelpermalwareS0385njRATmalwareS0391HAWKBALLmalwareS0401Exaramel for LinuxmalwareS0412ZxShellmalwareS0414BabySharkmalwareS0428PoetRATmalwareS0431HotCroissantmalwareS0433RifdoormalwareS0439OkrummalwareS0441PowerShowermalwareS0447LokibotmalwareS0448Rising SunmalwareS0450SHARPSTATSmalwareS0455MetamorfomalwareS0456Aria-bodymalwareS0459MechaFloundermalwareS0460Get2malwareS0461SDBbotmalwareS0476ValakmalwareS0477GoopymalwareS0486BonadanmalwareS0498CryptoisticmalwareS0513LiteDukemalwareS0514WellMessmalwareS0515WellMailmalwareS0521BloodHoundtoolS0531GrandoreiromalwareS0532LucifermalwareS0533SLOTHFULMEDIAmalwareS0534BazarmalwareS0543SparkmalwareS0554EgregormalwareS0559SUNBURSTmalwareS0568EVILNUMmalwareS0569ExplosivemalwareS0572Caterpillar WebShellmalwareS0590NBTscantoolS0596ShadowPadmalwareS0610SideTwistmalwareS0615SombRATmalwareS0627SodaMastermalwareS0631ChaesmalwareS0632GrimAgentmalwareS0635BoomBoxmalwareS0644ObliqueRATmalwareS0647TurianmalwareS0649SMOKEDHAMmalwareS0650QakBotmalwareS0652MarkiRATmalwareS0657BLUELIGHTmalwareS0659DiavolmalwareS0660ClamblingmalwareS0662RCSessionmalwareS0663SysUpdatemalwareS0666GelsemiummalwareS0667ChrommmemalwareS0673DarkWatchmanmalwareS0680LitePowermalwareS0681LizarmalwareS0691NeoichormalwareS0692SILENTTRINITYtoolS0694DRATzarusmalwareS0696FlagpromalwareS1013ZxxZmalwareS1015MilanmalwareS1016MacMamalwareS1018Saint BotmalwareS1021DnsSystemmalwareS1024CreepySnailmalwareS1025AmadeymalwareS1028Action RATmalwareS1029AuTo StealermalwareS1030SquirrelwafflemalwareS1032PyDCryptmalwareS1034StrifeWatermalwareS1035Small SievemalwareS1037STARWHALEmalwareS1039BumblebeemalwareS1044FunnyDreammalwareS1059metaMainmalwareS1060MafaldamalwareS1064SVCReadymalwareS1065Woody RATmalwareS1068BlackCatmalwareS1075KOPILUWAKmalwareS1081BADHATCHmalwareS1087AsyncRATtoolS1106NGLitemalwareS1124SocGholishmalwareS1130Raspberry RobinmalwareS1141LunarWebmalwareS1146MgBotmalwareS1147NightdoormalwareS1148Raccoon StealermalwareS1149CHIMNEYSWEEPmalwareS1153Cuckoo StealermalwareS1160LatrodectusmalwareS1169MangomalwareS1172OilBoostermalwareS1207XLoadermalwareS1226BOOKWORMmalwareS1228PUBLOADmalwareS1229HavocmalwareS1239TONESHELLmalwareS1240RedLine StealermalwareS1245InvisibleFerretmalwareS1248XORIndex LoadermalwareS1249HexEval LoadermalwareS9019PureCryptermalwareS9020LODEINFOmalwareS9023HiddenFacemalwareS9029IronWindmalwareS9035LAMEHUGmalwareS9037RustyWatermalware

▪Reference

T1033on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.