Local Accounts

T1078.003

Sub-technique of T1078 Valid Accounts.View on attack.mitre.org

About this technique

Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.

Detection rules11

Rules on DetectionCode tagged with T1078.003.

Sigma5

RuleLevelLog source
Root Account Enable Via Dsenablerootmediummacos / process_creation
User Added To Admin Group Via Dsclmediummacos / process_creation
User Added To Admin Group Via DseditGroupmediummacos / process_creation
User Added To Admin Group Via Sysadminctlmediummacos / process_creation
Admin User Remote Logonlowwindows / NULL

Splunk6

RuleTypeRiskData source
Cisco ASA - New Local User Account CreatedAnomalyNULLCisco ASA Logs
Cisco ASA - User Privilege Level ChangeAnomalyNULLCisco ASA Logs
Detect Excessive User Account LockoutsAnomalyNULL
Potential password in usernameHuntingNULLLinux Secure
Short Lived Windows AccountsTTPNULLWindows Event Log System 4720, Windows Event Log System 4726
Windows Builtin Account Name Was ChangedTTPNULLWindows Event Log Security 4781

Groups12

Software5

Campaigns4

Procedure examples21

Groups12

Used byProcedure example
GroupAPT29

APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence.

GroupAPT32

APT32 has used legitimate local admin account credentials.

GroupFIN10

FIN10 has moved laterally using the Local Administrator account.

GroupFIN7

FIN7 has used compromised credentials for access as SYSTEM on Exchange servers.

GroupHAFNIUM

HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers.

GroupKimsuky

Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP.

GroupPlay

Play has used valid local accounts to gain initial access.

GroupPROMETHIUM

PROMETHIUM has created admin accounts on a compromised host.

View all 12 groups examples

Software5

Used byProcedure example
MalwareCobalt Strike

Cobalt Strike can use known credentials to run commands and spawn processes as a local user account.

MalwareEmotet

Emotet can brute force a local admin password, then use it to facilitate lateral movement.

MalwareLockBit 3.0

LockBit 3.0 can use a compromised local account for lateral movement.

MalwareNotPetya

NotPetya can use valid credentials with PsExec or wmic to spread itself to remote systems.

MalwareUmbreon

Umbreon creates valid local users to provide access to the system.

Campaigns4

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to test credentials harvested against discovered devices.

CampaignLeviathan Australian Intrusions

Leviathan used captured local account information, such as service accounts, for actions during Leviathan Australian Intrusions.

CampaignOperation Wocao

During Operation Wocao, threat actors used local account credentials found during the intrusion for lateral movement and privilege escalation.

CampaignSolarWinds Compromise

During the SolarWinds Compromise, APT29 used compromised local accounts to access victims' networks.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.