If you are not sure if the website you would like to visit is secure, you can verify it here. Enter the website address of the page and see parts of its content and the thumbnail images on this site. None (if any) dangerous scripts on the referenced page will be executed. Additionally, if the selected site contains subpages, you can verify it (review) in batches containing 5 pages.
favicon.ico: attack.mitre.org/techniques/T1589/003 - Gather Victim Identity Informa.

site address: attack.mitre.org/techniques/T1589/003 redirected to: attack.mitre.org/techniques/T1589/003

site title: Gather Victim Identity Information: Employee Names, Sub-technique T1589.003 - Enterprise MITRE ATT&CK®

Our opinion (on Tuesday 18 August 2026 23:22:24 UTC):

GREEN status (no comments) - no comments
After content analysis of this website we propose the following hashtags:



Meta tags:

Headings (most frequently used words):

gather, victim, identity, information, employee, names, procedure, examples, mitigations, detection, strategy, references, other, sub, techniques, of,

Text of the page (most frequently used words):
att (10), and (10), all (10), #employee (10), the (9), names (9), enterprise (8), information (8), victim (7), #detection (6), may (6), t1589 (6), gather (6), ics (5), mobile (5), none (5), data (5), techniques (5), for (5), mitre (4), defenses (4), sub (4), retrieved (4), october (4), reconnaissance (4), name (4), version (4), other (4), identity (4), domains (3), resources (3), cti (3), mitigations (3), 2020 (3), phishing (3), efforts (3), this (3), description (3), technique (3), 003 (3), search (3), 2026 (2), corporation (2), are (2), reference (2), campaigns (2), software (2), groups (2), components (2), analytics (2), strategies (2), assets (2), tactics (2), matrices (2), core (2), objects (2), march (2), 2021 (2), target (2), resource (2), 2024 (2), cybersecurity (2), during (2), initial (2), access (2), well (2), outside (2), analytic (2), easily (2), with (2), controls (2), since (2), available (2), pre (2), compromise (2), has (2), collected (2), organizations (2), silent (2), librarian (2), sandworm (2), team (2), kimsuky (2), adversaries (2), accounts (2), open (2), websites (2), can (2), used (2), email (2), addresses (2), more (2), ckcon (2), person (2), tickets (2), faq (2), 2015, registered, trademarks, cookie, preferences, website, changelog, privacy, policy, terms, use, contact, reset, filters, doj, 2018, rafatnejad, february, scott, brady, united, states, yuriy, sergeyevich, andrienko, november, kisa, attack, analysis, operation, muzabi, center, incidents, september, references, focused, related, stages, adversary, lifecycle, such, much, activity, have, very, high, occurrence, associated, false, positive, rate, potentially, taking, place, visibility, organization, making, difficult, defenders, an1989, det0857, strategy, cannot, mitigated, preventive, based, behaviors, performed, scope, should, focus, minimizing, amount, sensitivity, external, parties, m1056, mitigation, lists, individuals, from, targeted, g0122, research, potential, included, identification, collection, g0034, g0094, procedure, examples, live, permalink, 2025, last, modified, created, platforms, tactic, they, readily, exposed, via, online, accessible, sets, gathering, reveal, opportunities, forms, establishing, operational, valid, owned, social, media, that, targeting, derive, help, guide, craft, believable, lures, 002, credentials, 001, home, join, mclean, hotel, location, details, found, register, here, blog, contribute, benefactors, legal, branding, updates, history, engage, tools, advisory, council, learn, about, get, started, detections,


Text of the page (random words):
gather victim identity information employee names sub technique t1589 003 enterprise mitre att ck matrices enterprise mobile ics tactics enterprise mobile ics techniques enterprise mobile ics defenses mitigations enterprise mobile ics assets detections detection strategies analytics data components cti groups software campaigns resources get started learn more about att ck att ck advisory council att ckcon att ck data tools faq engage with att ck version history updates legal branding benefactors contribute blog search att ckcon 7 0 in person tickets are open join us october 27 28 2026 in mclean va register here for in person tickets hotel and location details can be found in the faq home techniques enterprise gather victim identity information employee names gather victim identity information employee names other sub techniques of gather victim identity information 3 id name t1589 001 credentials t1589 002 email addresses t1589 003 employee names adversaries may gather employee names that can be used during targeting employee names be used to derive email addresses as well as to help guide other reconnaissance efforts and or craft more believable lures adversaries may easily gather employee names since they may be readily available and exposed via online or other accessible data sets ex social media or search victim owned websites 1 gathering this information may reveal opportunities for other forms of reconnaissance ex search open websites domains or phishing for information establishing operational resources ex compromise accounts and or initial access ex phishing or valid accounts id t1589 003 sub technique of t1589 ⓘ tactic reconnaissance ⓘ platforms pre version 1 0 created 02 october 2020 last modified 24 october 2025 version permalink live version procedure examples id name description g0094 kimsuky kimsuky has collected victim employee name information 2 g0034 sandworm team sandworm team s research of potential victim organizations included the identification and collection of employee information 3 g0122 silent librarian silent librarian has collected lists of names for individuals from targeted organizations 4 mitigations id mitigation description m1056 pre compromise this technique cannot be easily mitigated with preventive controls since it is based on behaviors performed outside of the scope of enterprise defenses and controls efforts should focus on minimizing the amount and sensitivity of data available to external parties detection strategy id name analytic id analytic description det0857 detection of employee names an1989 much of this activity may have a very high occurrence and associated false positive rate as well as potentially taking place outside the visibility of the target organization making detection difficult for defenders detection efforts may be focused on related stages of the adversary lifecycle such as during initial access references cybersecurity resource center n d cybersecurity incidents retrieved september 16 2024 kisa 2021 phishing target reconnaissance and attack resource analysis operation muzabi retrieved march 8 2024 scott w brady 2020 october 15 united states vs yuriy sergeyevich andrienko et al retrieved november 25 2020 doj 2018 march 23 u s v rafatnejad et al retrieved february 3 2021 core objects all core att ck objects all none matrices tactics techniques sub techniques defenses all defenses all none mitigations assets detection strategies analytics data components cti all cti all none groups software campaigns reference all reference all none resources domains all domains all none enterprise mobile ics reset filters contact us terms of use privacy policy website changelog cookie preferences 2015 2026 the mitre corporation mitre att ck and att ck are registered trademarks of the mitre corporation
Thumbnail images (randomly selected): * Images may be subject to copyright.GREEN status (no comments)
  • External site

Verified site has: 58 subpage(s). Do you want to verify them? Verify pages:

1-5 6-10 11-15 16-20 21-25 26-30 31-35 36-40 41-45 46-50
51-55 56-58


The site also has references to the 1 subdomain(s)

  mitre.org  Verify


The site also has 1 references to other resources (not html/xhtml )

 web.archive.org/web/20220328121326/htt___.pdf  Verify


Top 50 hastags from of all verified websites.

Supplementary Information (add-on for SEO geeks)*- See more on header.verify-www.com

Header

HTTP/1.1 301 Moved Permanently
Connection close
Content-Length 162
Server GitHub.com
Content-Type text/html
Location htt????/attack.mitre.org/techniques/T1589/003
X-GitHub-Request-Id 158C:3D0961:495A39:49C673:6A84E92F
x-github-edge-region fra
Accept-Ranges bytes
Age 0
Date Tue, 18 Aug 2026 23:22:24 GMT
Via 1.1 varnish
X-Served-By cache-rtm-ehrd2290043-RTM
X-Cache MISS
X-Cache-Hits 0
X-Timer S1787095344.945870,VS0,VE102
Vary Accept-Encoding
X-Fastly-Request-ID 2f81ad39725d9ce995311238a45b07e0f25d1670
HTTP/2 301
server GitHub.com
content-type text/html
location htt????/attack.mitre.org/techniques/T1589/003/
access-control-allow-origin *
expires Tue, 18 Aug 2026 23:32:24 GMT
cache-control max-age=600
x-proxy-cache MISS
x-github-request-id 8B5C:356974:5111A:556A5:6A84E930
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Tue, 18 Aug 2026 23:22:24 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630073-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787095344.074157,VS0,VE86
vary Accept-Encoding
x-fastly-request-id da3a754166dbda997771bf02e384f36f6c443216
content-length 162
HTTP/2 200
server GitHub.com
content-type text/html; charset=utf-8
x-origin-cache HIT
last-modified Fri, 07 Aug 2026 14:24:18 GMT
access-control-allow-origin *
etag W/ 6a75ea92-aa99
expires Tue, 18 Aug 2026 23:32:24 GMT
cache-control max-age=600
content-encoding gzip
x-proxy-cache MISS
x-github-request-id B218:30CBB0:4C7AF:50CDE:6A84E92F
x-github-edge-region uksouth
accept-ranges bytes
age 0
date Tue, 18 Aug 2026 23:22:24 GMT
via 1.1 varnish
x-served-by cache-lcy-egml8630073-LCY
x-cache MISS
x-cache-hits 0
x-timer S1787095344.167585,VS0,VE90
vary Accept-Encoding
x-fastly-request-id 8d1e2644b9b8aff0d2e15857a027c6f2684a373c
content-length 7383

Meta Tags

title="Gather Victim Identity Information: Employee Names, Sub-technique T1589.003 - Enterprise | MITRE ATT&CK®"
name="google-site-verification" content="2oJKLqNN62z6AOCb0A0IXGtbQuj-lev5YPAHFF_cbHQ"
charset="utf-8"
name="viewport" content="width=device-width, initial-scale=1,shrink-to-fit=no"
http-equiv="X-UA-Compatible" content="IE=edge"

Load Info

page size7383
load time (s)0.594327
redirect count2
speed download12429
server IP 185.199.109.153
* all occurrences of the string "http://" have been changed to "htt???/"