T1136 Create Account
Adversaries may create an account to maintain access to victim systems.(Citation: Symantec WastedLocker June 2020) With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system. Accounts may be created on the local system or within a domain or cloud tenant. In cloud…
Who uses it · with stories on Jábega
Sigma rules to hunt it
- Serv-U Exploitation CVE-2021-35211 by DEV-0322criticaltest · windows
- Cisco Local Accountshightest · cisco
- Creation of a Local Hidden User Account by Registryhightest · windows
- DarkGate - User Created Via Net.EXEhightest · windows
- Hidden Local User Creationhightest · windows
- New User Created Via Net.EXE With Never Expire Optionhightest · windows
- PSEXEC Remote Execution File Artefacthightest · windows
- Privileged User Has Been Createdhightest · linux
- Suspicious Windows ANONYMOUS LOGON Local Account Createdhightest · windows
- User Added to Remote Desktop Users Grouphightest · windows
- Creation Of An User Accountmediumtest · linux
- ESXi Account Creation Via ESXCLImediumtest · linux
- Manipulation of User Computer or Group Security Principals Across ADmediumtest · windows
- New Federated Domain Added - Exchangemediumtest · m365
- New User Created Via Net.EXEmediumtest · windows
- PowerShell Create Local Usermediumtest · windows
- FortiGate - New Administrator Account Createdmediumexperimental · fortigate
- FortiGate - New Local User Createdmediumexperimental · fortigate
Rules from SigmaHQ · Detection Rule License 1.1. Technique from MITRE ATT&CK®.