From e843ca71e7e2eb5fd1c63714800ea4443424bf63 Mon Sep 17 00:00:00 2001 From: Michael Haag <“mike@redcanary.com git config --global user.name “Michael Haag> Date: Wed, 8 Nov 2017 22:19:10 -0800 Subject: [PATCH] Linux + Add Account Discovery + Fix Cron Job title --- Linux/Discovery/Account_Discovery.md | 17 +++++++++++++++++ Linux/Persistence/Cron_Job.md | 2 +- 2 files changed, 18 insertions(+), 1 deletion(-) create mode 100644 Linux/Discovery/Account_Discovery.md diff --git a/Linux/Discovery/Account_Discovery.md b/Linux/Discovery/Account_Discovery.md new file mode 100644 index 00000000..307df472 --- /dev/null +++ b/Linux/Discovery/Account_Discovery.md @@ -0,0 +1,17 @@ +# Account Discovery + +MITRE ATT&CK Technique: [T1087](https://attack.mitre.org/wiki/Technique/T1087) + +List of all accounts: + + cat /etc/passwd + +Currently logged in: + +Local: + + finger + +Remote: + + finger @ diff --git a/Linux/Persistence/Cron_Job.md b/Linux/Persistence/Cron_Job.md index bd2891b4..09435f6a 100644 --- a/Linux/Persistence/Cron_Job.md +++ b/Linux/Persistence/Cron_Job.md @@ -1,4 +1,4 @@ -# Bash History +# Cron Job MITRE ATT&CK Technique: [T1168](https://attack.mitre.org/wiki/Technique/T1168)