Gold Open Source
ExplorePackagesVulnerabilitiesCWEsMCP ServersScan
Login
Gold Open Source

The authoritative source for production-ready open-source components. Every package, container image, AI model, and MCP server undergoes rigorous verification for security, malware, and license compliance.

Explore Gold

  • Explore Everything
  • Packages
  • Gold Certified Packages
  • Container Images
  • AI Models
  • MCP Servers
  • Agent Skills
  • Chip Manufacturers

Security Data & Tools

  • Scan Your Dependencies
  • Trending Threats
  • Threat RSS Feeds
  • CVE Database
  • Actively Exploited (KEV)
  • SGZ Zero-Days
  • CWE Index
  • MITRE ATT&CK
  • Malicious Packages
  • Security Glossary
  • Supply-Chain Report
  • Developers (API & Badge)
  • Chrome Extension
  • Credits & Data Sources

Products

  • The Platform
  • ESSCM
  • Portal
  • TPRM
  • OSM
  • Cowork
  • Code / Runner
  • Guard

Use Cases

  • Know Your Software
  • Auto-Fix Vulnerabilities
  • Asset Discovery
  • AI Governance
  • MCP Server Security
  • Supply Chain Compliance
  • Zero-Day Discovery
  • All Use Cases

Company

  • About
  • Pricing
  • Blog
  • Documentation
  • Safeguard Academy
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 Gold Open Source. All rights reserved.

Built with care bySafeguard
Home/ATT&CK/T1069/T1069.001
MITRE ATT&CK Sub-Technique

T1069.001: Local Groups

ShareXLinkedInRedditHN

Adversaries may attempt to find local system groups and permission settings. The knowledge of local system permission groups can help adversaries determine which groups exist and which users belong to a particular group. Adversaries may use this information to determine which users have elevated permissions, such as the users found within the local administrators group. Commands such as <code>net localgroup</code> of the [Net](https://attack.mitre.org/software/S0039) utility, <code>dscl . -list /Groups</code> on macOS, and <code>groups</code> on Linux can list local groups.

Tactics
Discovery
Platforms
Linux, macOS, Windows

▪Parent technique

T1069: Permission Groups Discovery

▪Used by groups (7)

G0010TurlaG0018admin@338G0049OilRigG0114ChimeraG0131Tonto TeamG1001HEXANEG1017Volt Typhoon

▪Software using this technique (21)

S0039NettoolS0060Sys10malwareS0082EmissarymalwareS0091EpicmalwareS0154Cobalt StrikemalwareS0165OSInfomalwareS0170HelminthmalwareS0184POWRUNERmalwareS0201JPINmalwareS0236KwampirsmalwareS0265KazuarmalwareS0378PoshC2toolS0381FlawedAmmyymalwareS0521BloodHoundtoolS0572Caterpillar WebShellmalwareS0650QakBotmalwareS0692SILENTTRINITYtoolS0696FlagpromalwareS1141LunarWebmalwareS1179ExbytemalwareS1198Gomirmalware

▪Reference

T1069.001on MITRE ATT&CK

MITRE ATT&CK® is a registered trademark of The MITRE Corporation. © 2026 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation.