BIOC Informational

Possible user enumeration via /etc/passwd

Attackers may enumerate users by reading the /etc/passwd file.

Module:
Platform Analytics
Agent event type:
Process execution
Category:
Discovery
Status:
Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Account Discovery (T1087)
Indicator:

Process action type = execution AND target process cmd = */etc/passwd*

Preventable: yes