Insider Threat Matrix™Insider Threat Matrix™
  • ID: PR044.002
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Contributor: The ITM Team

Directory and Domain Account Discovery

A subject identifies or enumerates accounts, groups, roles, and related identity attributes maintained within a centralized organizational directory or domain.

 

The subject may use directory queries, Lightweight Directory Access Protocol requests, PowerShell commands, operating-system utilities, identity-management interfaces, scripts, or administrative tools to identify usernames, group memberships, account status, organizational relationships, delegated permissions, or other directory attributes.

 

The activity may be broad, such as retrieving a complete list of directory identities, or targeted toward a particular department, role, security group, executive, administrator, or dormant account. Investigators should assess the query scope, search filters, number and type of identities returned, originating account and endpoint, and whether the subject later attempted to access or collect credentials for any discovered identity.