Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR044.001
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Contributor: The ITM Team

Local Account Discovery

A subject identifies or enumerates accounts configured on an endpoint, server, appliance, or other local operating system.

 

The subject may use operating-system commands, account-management utilities, scripts, registry data, configuration files, or administrative interfaces to identify local usernames, account identifiers, group memberships, account status, last-logon information, or locally assigned privileges.

 

Local account discovery may support later credential collection, unauthorized access, impersonation, privilege elevation, persistence, or movement to another account on the same system. Investigators should assess the commands or tools used, the number of systems queried, the subject’s normal administrative responsibilities, and any subsequent activity involving the discovered accounts.