BIOC
Informational
✕
Possible user enumeration via /etc/passwd
Attackers may enumerate users by reading the /etc/passwd file.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Discovery
- Status:
- Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Account Discovery (T1087)
Indicator:
Process action type = execution AND target process cmd = */etc/passwd*
Preventable: yes