Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR044
  • Created: 19th July 2026
  • Updated: 19th July 2026
  • MITRE ATT&CK®: T1087T1087.001T1087.002T1087.003T1087.004
  • Contributor: The ITM Team

Account Discovery

A subject identifies or enumerates accounts, identities, groups, roles, privileges, or related account attributes within organizational systems in preparation for an infringement. The activity may involve local operating system accounts, directory or domain identities, email accounts, cloud identities, service accounts, shared accounts, application accounts, administrative groups, or other privileged and high-value identities.

 

Account discovery may be conducted through operating system commands, directory queries, administrative consoles, identity platforms, email address lists, cloud control planes, application interfaces, scripts, configuration files, or other organizational data sources. The subject may use the information to identify potential targets for credential collection, unauthorized account access, impersonation, privilege escalation, persistence, or movement between systems.

 

Investigators should assess the method used, the volume and type of accounts identified, the subject’s legitimate requirement to access the information, and any subsequent activity involving the discovered identities. Particular attention should be given to enumeration of privileged, dormant, service, shared, executive, security, or administrative accounts outside the subject’s normal responsibilities.

Subsections (6)

ID Name Description
PR044.005Application, Service, and Shared Account Discovery

A subject identifies or enumerates accounts maintained within an individual application or accounts used by services, integrations, automation, scheduled processes, or multiple authorized individuals.

 

The subject may review application administration pages, account directories, configuration files, deployment definitions, service documentation, scripts, database records, secrets-management metadata, or account inventories to identify application users, service accounts, integration identities, shared accounts, account owners, or associated privileges.

 

These accounts may be attractive because they can hold broad access, operate without interactive oversight, or provide weaker attribution than a personally assigned identity. Discovery may support later credential collection, unauthorized application access, misuse of automation, persistence, or concealment through a non-personal identity.

 

Investigators should determine how the account information was obtained, whether the subject had an operational requirement to view it, which account types were targeted, and whether discovered identities were later used interactively or outside their documented purpose.

PR044.004Cloud Identity Discovery

A subject identifies or enumerates users, groups, roles, guest identities, service principals, managed identities, application identities, or other accounts maintained within a cloud environment.

 

The subject may use a cloud administration portal, command-line interface, software development kit, application programming interface, identity platform, or script to retrieve identity and access information. The resulting data may include account names, role assignments, group memberships, authentication methods, account status, tenant relationships, or access to cloud resources.

 

Cloud identity discovery may enable later credential collection, privilege elevation, unauthorized cloud access, impersonation, persistence, or movement between subscriptions, projects, accounts, tenants, or services. Investigators should examine cloud control-plane audit events, identity-listing operations, query volume, resources queried, originating identity, and subsequent activity involving discovered accounts or roles.

PR044.002Directory and Domain Account Discovery

A subject identifies or enumerates accounts, groups, roles, and related identity attributes maintained within a centralized organizational directory or domain.

 

The subject may use directory queries, Lightweight Directory Access Protocol requests, PowerShell commands, operating-system utilities, identity-management interfaces, scripts, or administrative tools to identify usernames, group memberships, account status, organizational relationships, delegated permissions, or other directory attributes.

 

The activity may be broad, such as retrieving a complete list of directory identities, or targeted toward a particular department, role, security group, executive, administrator, or dormant account. Investigators should assess the query scope, search filters, number and type of identities returned, originating account and endpoint, and whether the subject later attempted to access or collect credentials for any discovered identity.

PR044.003Email Account Discovery

A subject identifies or enumerates organizational email accounts, mailboxes, aliases, distribution lists, shared mailboxes, or other messaging identities in preparation for an infringement.

 

The subject may search a corporate address book, query an email administration interface, review message headers, enumerate valid recipients, export directory information, use scripts or application programming interfaces, or inspect configuration data containing email addresses.

 

Email account discovery may be used to identify targets for impersonation, social engineering, unauthorized mailbox access, information collection, or communication with selected members of the population. Particular concern should be given to enumeration of executive, legal, Human Resources, security, finance, shared, or otherwise sensitive mailboxes outside the subject’s normal responsibilities.

 

Investigators should assess the volume and pattern of searches, whether unusual address lists were exported, the subject’s legitimate communication requirements, and any subsequent messages, mailbox access, impersonation attempts, or credential activity involving the discovered accounts.

PR044.001Local Account Discovery

A subject identifies or enumerates accounts configured on an endpoint, server, appliance, or other local operating system.

 

The subject may use operating-system commands, account-management utilities, scripts, registry data, configuration files, or administrative interfaces to identify local usernames, account identifiers, group memberships, account status, last-logon information, or locally assigned privileges.

 

Local account discovery may support later credential collection, unauthorized access, impersonation, privilege elevation, persistence, or movement to another account on the same system. Investigators should assess the commands or tools used, the number of systems queried, the subject’s normal administrative responsibilities, and any subsequent activity involving the discovered accounts.

PR044.006Privileged and High-Value Account Discovery

A subject specifically identifies or enumerates privileged, administrative, executive, security, dormant, emergency, or other high-value organizational identities.

 

The subject may search for membership of administrative groups, privileged cloud roles, domain administrators, security personnel, executive accounts, service accounts with elevated access, emergency access identities, or accounts with authority over sensitive systems and business processes.

 

This behavior is distinct from broad account discovery because the subject selectively targets identities whose authority, access, organizational position, or reduced oversight could support a later infringement. The discovered identities may be targeted for credential collection, impersonation, privilege elevation, persistence, unauthorized approval, or anti-forensic account misuse.

 

Investigators should examine the names, roles, groups, and attributes queried; whether the subject searched for terminology associated with elevated access; and whether the activity was followed by credential access, authentication attempts, social engineering, or requests involving the identified accounts.