Skip to content
Skip to main content
Cyber Incidents & Offender Methods Technical Explainer

What is account discovery?

Account discovery is activity used to find which users, service accounts, administrators or groups exist in an environment.

That can be very useful to an investigator because the names returned by the query may later reappear in authentication records, privilege changes or access to another system.

What might somebody be looking for?

A person who has reached a Windows system may want to know:

  • which user is currently logged in;
  • which local or domain accounts exist;
  • which accounts are administrators;
  • whether service accounts are present; or
  • which groups have useful access.

A simple result might look like:

Administrator
jpatel
svc-backup
helpdesk-admin

At that point, svc-backup and helpdesk-admin become obvious values to look for later.

The useful evidence is the query and the result

Where possible, keep both.

A process or audit record may show the query itself. Console output, redirected files or directory logs may show what came back.

QueryWhich accounts exist?Command, API call, directory search or management tool.
Resultsvc-backup appearsThe session now knows that identity exists.
Follow-onAuthentication uses the same nameLater records show whether the discovered identity was actually targeted or used.

That sequence is much more useful than simply saying “account discovery happened”.

Do not confuse finding an account with using it

If an account appears in a list, all you know at that point is that it was visible to the query.

You do not yet know:

  • whether anybody knew the password;
  • whether the credentials were valid;
  • whether the account was later used;
  • whether access succeeded; or
  • whether the named account holder was involved.

So take the exact account name or identifier and search for it in later authentication, directory and target-system records.

Does reconnaissance prove the next stage of an attack occurred? shows how that progression works.

Legitimate systems do this too

Directory synchronisation, support tools, security platforms and administrators routinely enumerate users and groups.

The surrounding sequence usually tells you more than the account list alone.

If a normal management platform runs the same query every morning, that is very different from a newly compromised workstation discovering privileged identities and then trying to authenticate with one of them.

The practical point is: account discovery tells you which identities became visible to the session. Those names are often some of the best pivots you have for finding what happened next.

Reference: CIM-122Cyber Incidents & Offender Methods