Sub-technique of T1078 Valid Accounts.View on attack.mitre.org
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.
Rules on DetectionCode tagged with T1078.003.
| Rule | Level | Log source |
|---|---|---|
| Root Account Enable Via Dsenableroot | medium | macos / process_creation |
| User Added To Admin Group Via Dscl | medium | macos / process_creation |
| User Added To Admin Group Via DseditGroup | medium | macos / process_creation |
| User Added To Admin Group Via Sysadminctl | medium | macos / process_creation |
| Admin User Remote Logon | low | windows / NULL |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco ASA - New Local User Account Created | Anomaly | NULL | Cisco ASA Logs |
| Cisco ASA - User Privilege Level Change | Anomaly | NULL | Cisco ASA Logs |
| Detect Excessive User Account Lockouts | Anomaly | NULL | |
| Potential password in username | Hunting | NULL | Linux Secure |
| Short Lived Windows Accounts | TTP | NULL | Windows Event Log System 4720, Windows Event Log System 4726 |
| Windows Builtin Account Name Was Changed | TTP | NULL | Windows Event Log Security 4781 |
| Used by | Procedure example |
|---|---|
| GroupAPT29 | APT29 targets dormant or inactive user accounts, accounts belonging to individuals no longer at the organization but whose accounts remain on the system, for access and persistence. |
| GroupAPT32 | APT32 has used legitimate local admin account credentials. |
| GroupFIN10 | FIN10 has moved laterally using the Local Administrator account. |
| GroupFIN7 | FIN7 has used compromised credentials for access as SYSTEM on Exchange servers. |
| GroupHAFNIUM | HAFNIUM has used the NT AUTHORITY\SYSTEM account to create files on Exchange servers. |
| GroupKimsuky | Kimsuky has used a tool called GREASE to add a Windows admin account in order to allow them continued access via RDP. |
| GroupPlay | Play has used valid local accounts to gain initial access. |
| GroupPROMETHIUM | PROMETHIUM has created admin accounts on a compromised host. |
| Used by | Procedure example |
|---|---|
| MalwareCobalt Strike | Cobalt Strike can use known credentials to run commands and spawn processes as a local user account. |
| MalwareEmotet | Emotet can brute force a local admin password, then use it to facilitate lateral movement. |
| MalwareLockBit 3.0 | LockBit 3.0 can use a compromised local account for lateral movement. |
| MalwareNotPetya | NotPetya can use valid credentials with PsExec or |
| MalwareUmbreon | Umbreon creates valid local users to provide access to the system. |
| Used by | Procedure example |
|---|---|
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to test credentials harvested against discovered devices. |
| CampaignLeviathan Australian Intrusions | Leviathan used captured local account information, such as service accounts, for actions during Leviathan Australian Intrusions. |
| CampaignOperation Wocao | During Operation Wocao, threat actors used local account credentials found during the intrusion for lateral movement and privilege escalation. |
| CampaignSolarWinds Compromise | During the SolarWinds Compromise, APT29 used compromised local accounts to access victims' networks. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.