Group metadata includes attributes like name, permissions, purpose, and associated user accounts or roles, which adversaries may exploit for privilege escalation. Examples:
Get-ADGroup -Identity "Domain Admins" -Properties Members, DescriptionGet-AzureADGroup -ObjectId <GroupId>GET https://admin.googleapis.com/admin/directory/v1/groups/<groupKey>aws iam list-group-policies --group-name <group_name>GET https://graph.microsoft.com/v1.0/groups/<id>Data Collection Measures:
| Name | Channel |
|---|---|
| m365:sharepoint | Enumerate ACLs/role bindings |
| ID | Name | Technique Detected |
|---|---|---|
| DET0251 | Behavioral Detection of Cloud Group Enumeration via API and CLI Access | T1069.003 |