AltaySec · ATLAS 2026.07
AML.T0087

Gather Victim Identity Information

C · Explainer (cannot be honestly simulated in-browser) AML.TA0002 · Reconnaissance

Description

Adversaries may gather information about the victim's identity that can be used during targeting. Information about identities may include a variety of details, including personal data (ex: employee names, email addresses, photos, etc.) as well as sensitive details such as credentials or multi-factor authentication (MFA) configurations. Adversaries may gather this information in various ways, such as direct elicitation, Search Victim-Owned Websites, or via leaked information on the black market. Adversaries may use the gathered victim data to Create Deepfakes and impersonate them in a convincing manner. This may create opportunities for adversaries to Establish Accounts under the impersonated identity, or allow them to perform convincing Phishing attacks.

Honesty-tier rationale

This technique is OSINT/scanning against real targets. It cannot be honestly simulated in the browser without misrepresenting real difficulty; at most a walkthrough over mock target data.

Source

← Back to the matrix