{
  "technique_id": "T1087",
  "name": "Account Discovery",
  "tactics": [
    "Discovery"
  ],
  "platforms": [
    "ESXi",
    "IaaS",
    "Identity Provider",
    "Linux",
    "macOS",
    "Office Suite",
    "SaaS",
    "Windows"
  ],
  "summary": "Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment. This information can help adversaries determine which accounts exist, which can aid in follow-on behavior such as brute-forcing, spear-phishing attacks, or account takeovers (e.g., [Valid Accounts](https://attack.mitre.org/techniques/T1078))...",
  "generated_by": "SOC Response Atlas by Basyrix"
}