If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1589/003 - Gather Victim Identity Informa.

site address: attack.mitre.org/techniques/T1589/003 redirected to: attack.mitre.org/techniques/T1589/003

site title: Gather Victim Identity Information: Employee Names, Sub-technique T1589.003 - Enterprise MITRE ATT&CK®

Our opinion (on Wednesday 19 August 2026 9:11:09 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

gather, victim, identity, information, employee, names, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of,

Text of the page (most frequently used words):
att (10), and (10), all (10), employee (10), the (9), names (9), enterprise (8), information (8), #victim (7), #detection (6), may (6), t1589 (6), gather (6), ics (5), mobile (5), none (5), data (5), techniques (5), for (5), mitre (4), defenses (4), sub (4), retrieved (4), october (4), reconnaissance (4), name (4), version (4), other (4), identity (4), domains (3), resources (3), cti (3), mitigations (3), 2020 (3), phishing (3), efforts (3), this (3), description (3), technique (3), 003 (3), search (3), 2026 (2), corporation (2), are (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), march (2), 2021 (2), target (2), resource (2), 2024 (2), cybersecurity (2), during (2), initial (2), access (2), well (2), outside (2), analytic (2), easily (2), with (2), controls (2), since (2), available (2), pre (2), compromise (2), has (2), collected (2), organizations (2), silent (2), librarian (2), sandworm (2), team (2), kimsuky (2), adversaries (2), accounts (2), open (2), websites (2), can (2), used (2), email (2), addresses (2), more (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, use, contact, reset, filters, doj, 2018, rafatnejad, february, scott, brady, united, states, yuriy, sergeyevich, andrienko, november, kisa, attack, analysis, operation, muzabi, center, incidents, september, references, focused, related, stages, adversary, lifecycle, such, much, activity, have, very, high, occurrence, associated, false, positive, rate, potentially, taking, place, visibility, organization, making, difficult, defenders, an1989, det0857, strategy, cannot, mitigated, preventive, based, behaviors, performed, scope, should, focus, minimizing, amount, sensitivity, external, parties, m1056, mitigation, lists, individuals, from, targeted, g0122, research, potential, included, identification, collection, g0034, g0094, procedure, examples, live, permalink, 2025, last, modified, created, platforms, tactic, they, readily, exposed, via, online, accessible, sets, gathering, reveal, opportunities, forms, establishing, operational, valid, owned, social, media, that, targeting, derive, help, guide, craft, believable, lures, 002, credentials, 001, home, join, mclean, hotel, location, details, found, register, here, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, about, get, started, detections,


Text of the page (random words):
gather victim identity information employee names sub technique t1589 003 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise gather victim identity information employee names gather victim identity information employee names other sub techniques of gather victim identity information 3 id name t1589 001 credentials t1589 002 email addresses t1589 003 employee names adversaries may gather employee names that can be used during targeting employee names be used to derive email addresses as well as to help guide other reconnaissance efforts and or craft more believable lures adversaries may easily gather employee names since they may be readily available and exposed via online or other accessible data sets ex social media or search victim owned websites 1 gathering this information may reveal opportunities for other forms of reconnaissance ex search open websites domains or phishing for information establishing operational resources ex compromise accounts and or initial access ex phishing or valid accounts id t1589 003 sub technique of t1589 ⓘ tactic reconnaissance ⓘ platforms pre version 1 0 created 02 october 2020 last modified 24 october 2025 version permalink live version procedure examples id name description g0094 kimsuky kimsuky has collected victim employee name information 2 g0034 sandworm team sandworm team s research of potential victim organizations included the identification and collection of employee information 3 g0122 silent librarian silent librarian has collected lists of names for individuals from targeted organizations 4 mitigations id mitigation description m1056 pre compromise this technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls efforts should focus on minimizing the amount and sensitivity of data available to external parties detection strategy id name analytic id analytic description det0857 detection of employee names an1989 much of this activity may have a very high occurrence and associated false positive rate as well as potentially taking place outside the visibility of the target organization making detection difficult for defenders detection efforts may be focused on related stages of the adversary lifecycle such as during initial access references cybersecurity resource center n d cybersecurity incidents retrieved september 16 2024 kisa 2021 phishing target reconnaissance and attack resource analysis operation muzabi retrieved march 8 2024 scott w brady 2020 october 15 united states vs yuriy sergeyevich andrienko et al retrieved november 25 2020 doj 2018 march 23 u s v rafatnejad et al retrieved february 3 2021 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Images from subpage: "attack.mitre.org/techniques/T1593/001" Verify
Images from subpage: "attack.mitre.org/techniques/T1594" Verify
Images from subpage: "attack.mitre.org/techniques/T1593" Verify
Images from subpage: "attack.mitre.org/techniques/T1598" Verify
Images from subpage: "attack.mitre.org/techniques/T1586" Verify

Verified site has: 58 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-58


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/2 301
server GitHub.com
content-type text/html
x-origin-cache HIT
location htt????/attack.mitre.org/techniques/T1589/003/
access-control-allow-origin *
expires Wed, 19 Aug 2026 09:21:09 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 3BEC:2C512C:14CA186:14ECAF0:6A85732D
x-github-edge-region fra
accept-ranges bytes
age 0
date Wed, 19 Aug 2026 09:11:09 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290029-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787130669.120241,VS0,VE103
vary Accept-Encoding
x-fastly-request-id 8e9612651b9acfdce2cdddb0cac6c98ec952b2b0
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:19 GMT
access-control-allow-origin *
etag W/ 6a75ea93-aa99
expires Wed, 19 Aug 2026 09:21:09 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id 395C:27762E:14CCDFE:14EF8BE:6A85732D
x-github-edge-region fra
accept-ranges bytes
age 0
date Wed, 19 Aug 2026 09:11:09 GMT
via 1.1 varnish
x-served-by cache-rtm-ehrd2290029-RTM
x-cache MISS
x-cache-hits 0
x-timer S1787130669.231710,VS0,VE133
vary Accept-Encoding
x-fastly-request-id 216de9eaa2fd89b1848ef800061e856e0833b5a8
content-length 7383

Meta Tags

title="Gather Victim Identity Information: Employee Names, Sub-technique T1589.003 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size7383
load time (s)0.488112
redirect count1
speed download15129
server IP 185.199.110.153
* all occurrences of the string "http://" have been changed to "htt???/"