Has gathered details on their intended victims to aid in social engineering efforts for leveraging tailored themes of attacks.1
Gather Victim Identity Information T1589
- Tactic
- Reconnaissance
- Platform
- PRE
- Version
- 1.3
- Created
- 02 October 2020
- Last modified
- 12 May 2026
- Contributors
- Jannie Li, Microsoft Threat Intelligence Center (MSTIC); Obsidian Security
Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, security question responses, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations.
Gather Victim Identity Information MITRE reference T1589
10 groups have been recorded using this technique. Newest first; each entry carries MITRE’s procedure text and a link to the group’s full record. Click a name to filter the rules below.
Has researched specific professional groups such as software developers for targeting.123456 Contagious Interview has also researched individuals who work in roles related to cryptocurrency and blockchain technologies.78
Has identified ways to engage targets by researching potential victims' interests and social or professional contacts.1
Has gathered victim identify information during pre-compromise reconnaissance. 1
Has researched employees to target for social engineering attacks.1
Has used information from previous data breaches to identify employee names to be used in social engineering.1
All 10 groups for this technique · 6 newest in this preview
2 campaigns have been recorded using this technique. Listed newest first; dates are year-granularity and attribution is MITRE’s.
For Operation Dream Job, Lazarus Group conducted extensive reconnaissance research on potential targets.1
During Operation Wocao, threat actors targeted people based on their organizational roles and privileges.1
All 2 campaigns for this technique
Offense vs defense T1589
Is defensive coverage keeping up with adversary use? Eight counts, each ranked against all 697 ATT&CK techniques. Attack sits left, defense right, so a shape leaning left means adversaries are better documented here than defenders are equipped. Hover any spoke for its percentile and the share of techniques that have more. The timeline below shows when each side arrived.
How it got here
Adversary activity (campaign spans) over cumulative rule output. Each source is plotted independently from zero, so neither line includes the other. Campaign dates are year-granularity.
Gather Victim Identity Information detection strategy DET0841
MITRE names one behaviour worth catching for this technique and breaks it into 1 analytic, one per platform. Each carries the log sources it needs and the fields you tune per environment.
Detection of Gather Victim Identity Information
AN1973 · PRE
Monitor for suspicious network traffic that could be indicative of probing for user information, such as large/iterative quantities of authentication requests originating from a single source (especially if the source is known to be associated with an adversary/botnet). Analyzing web metadata may also reveal artifacts that can be attributed to potentially malicious activity, such as referer or user-agent string HTTP/S fields.
Log sources
The data this analytic draws on. You do not need every component — each one you already collect covers part of it. Each links to its ATT&CK record.
| Data component | Name | Channel |
|---|---|---|
| Network Traffic ContentDC0085 | Network Traffic | None |
This technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls. Efforts should focus on minimizing the amount and sensitivity of data available to external parties.