Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR044
  • Created: 19th July 2026
  • Updated: 19th July 2026
  • MITRE ATT&CK®: T1087T1087.001T1087.002T1087.003T1087.004
  • Contributor: The ITM Team

Account Discovery

A subject identifies or enumerates accounts, identities, groups, roles, privileges, or related account attributes within organizational systems in preparation for an infringement. The activity may involve local operating system accounts, directory or domain identities, email accounts, cloud identities, service accounts, shared accounts, application accounts, administrative groups, or other privileged and high-value identities.

 

Account discovery may be conducted through operating system commands, directory queries, administrative consoles, identity platforms, email address lists, cloud control planes, application interfaces, scripts, configuration files, or other organizational data sources. The subject may use the information to identify potential targets for credential collection, unauthorized account access, impersonation, privilege escalation, persistence, or movement between systems.

 

Investigators should assess the method used, the volume and type of accounts identified, the subject’s legitimate requirement to access the information, and any subsequent activity involving the discovered identities. Particular attention should be given to enumeration of privileged, dormant, service, shared, executive, security, or administrative accounts outside the subject’s normal responsibilities.