{
  "technique_id": "T1033",
  "name": "System Owner/User Discovery",
  "tactics": [
    "Discovery"
  ],
  "platforms": [
    "Linux",
    "macOS",
    "Network Devices",
    "Windows"
  ],
  "summary": "Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system. They may do this, for example, by retrieving account usernames or by using [OS Credential Dumping](https://attack.mitre.org/techniques/T1003)...",
  "generated_by": "SOC Response Atlas by Basyrix"
}