T1589Techniquereconnaissanceagent-callable
T1589Gather Victim Identity Information
Platforms: PRE
ATT&CK version: 14.1
What it is
Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, etc.) as well as sensitive details such as credentials.
Adversaries may gather this information in various ways, such as direct elicitation via [Phishing for Information](https://attack.mitre.org/techniques/T1598). Information about users could also be enumerated via other active means (i.e. [Active Scanning](https://attack.mitre.org/techniques/T1595)) such as probing and analyzing responses from authentication services that may reveal valid usernames in a system.(Citation: GrimBlog UsernameEnum) Information about victims may also be exposed to adversaries via online or other accessible data sets (ex: [Social Media](https://attack.mitre.org/techniques/T1593/001) or [Search Victim-Owned Websites](https://attack.mitre.org/techniques/T1594)).(Citation: OPM Leak)(Citation: Register Deloitte)(Citation: Register Uber)(Citation: Detectify Slack Tokens)(Citation: Forbes GitHub Creds)(Citation: GitHub truffleHog)(Citation: GitHub Gitrob)(Citation: CNET Leaks)
Gathering this information may reveal opportunities for other forms of reconnaissance (ex: [Search Open Websites/Domains](https://attack.mitre.org/techniques/T1593) or [Phishing for Information](https://attack.mitre.org/techniques/T1598)), establishing operational resources (ex: [Compromise Accounts](https://attack.mitre.org/techniques/T1586)), and/or initial access (ex: [Phishing](https://attack.mitre.org/techniques/T1566) or [Valid Accounts](https://attack.mitre.org/techniques/T1078)).
ATT&CK tactics· 1
References
- https://attack.mitre.org/techniques/T1589
- https://www.opm.gov/cybersecurity/cybersecurity-incidents/
- https://labs.detectify.com/2016/04/28/slack-bot-token-leakage-exposing-business-critical-information/
- https://github.com/dxa4481/truffleHog
- https://grimhacker.com/2017/07/24/office365-activesync-username-enumeration/
- https://www.theregister.com/2015/02/28/uber_subpoenas_github_for_hacker_details/
- https://github.com/michenriksen/gitrob
- https://www.cnet.com/news/massive-breach-leaks-773-million-emails-21-million-passwords/
- https://www.forbes.com/sites/runasandvik/2014/01/14/attackers-scrape-github-for-cloud-service-credentials-hijack-account-to-mine-virtual-currency/#242c479d3196
- https://www.theregister.com/2017/09/26/deloitte_leak_github_and_google/