Local Account

T1136.001

Sub-technique of T1136 Create Account.View on attack.mitre.org

About this technique

Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

For example, with a sufficient level of access, the Windows net user /add command can be used to create a local account. In Linux, the `useradd` command can be used, while on macOS systems, the dscl -create command can be used. Local accounts may also be added to network devices, often via common Network Device CLI commands such as username, to ESXi servers via `esxcli system account add`, or to Kubernetes clusters using the `kubectl` utility.

Adversaries may also create new local accounts on network firewall management consoles – for example, by exploiting a vulnerable firewall management system, threat actors may be able to establish super-admin accounts that could be used to modify firewall rules and gain further access to the network.

Such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.

Detection rules30

Rules on DetectionCode tagged with T1136.001.

Sigma16

RuleLevelLog source
Cisco Local Accountshighcisco / NULL
Creation of a Local Hidden User Account by Registryhighwindows / registry_event
Hidden Local User Creationhighwindows / NULL
New User Created Via Net.EXE With Never Expire Optionhighwindows / process_creation
Privileged User Has Been Createdhighlinux / NULL
Suspicious Windows ANONYMOUS LOGON Local Account Createdhighwindows / NULL
User Added to Remote Desktop Users Grouphighwindows / process_creation
Creation Of An User Accountmediumlinux / NULL
FortiGate - New Administrator Account Createdmediumfortigate / NULL
FortiGate - New Local User Createdmediumfortigate / NULL
New User Account Creation Attempt Via ADSImediumwindows / ps_script
New User Account Creation Attempt Via ADSI in CommandLinemediumwindows / process_creation
New User Created Via Net.EXEmediumwindows / process_creation
PowerShell Create Local Usermediumwindows / ps_script
Creation Of A Local User Accountlowmacos / process_creation

Splunk14

RuleTypeRiskData source
Cisco ASA - New Local User Account CreatedAnomalyNULLCisco ASA Logs
Create local admin accounts using net exeTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Detect New Local Admin accountTTPNULLWindows Event Log Security 4732, Windows Event Log Security 4720
ESXi Account ModifiedAnomalyNULLVMWare ESXi Syslog
Linux Add User AccountHuntingNULLSysmon for Linux EventID 1, Cisco Isovalent Process Exec
Linux Auditd Add User AccountAnomalyNULLLinux Auditd Proctitle
Linux Auditd Add User Account TypeAnomalyNULLLinux Auditd Add User
Short Lived Windows AccountsTTPNULLWindows Event Log System 4720, Windows Event Log System 4726
Windows Create Local AccountAnomalyNULLWindows Event Log Security 4720
Windows Create Local Administrator Account Via NetAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows ESX Admins Group Creation Security EventTTPNULLWindows Event Log Security 4727, Windows Event Log Security 4730, Windows Event Log Security 4737
Windows ESX Admins Group Creation via NetTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows ESX Admins Group Creation via PowerShellTTPNULLPowershell Script Block Logging 4104
Windows Privileged Group ModificationTTPNULLWindows Event Log Security 4727, Windows Event Log Security 4731, Windows Event Log Security 4744, Windows Event Log Security 4749, Windows Event Log Security 4754, Windows Event Log Security 4756, Windows Event Log Security 4759, Windows Event Log Security 4783, Windows Event Log Security 4790

Groups14

Software15

Campaigns1

Procedure examples30

Groups14

Used byProcedure example
GroupAPT3

APT3 has been known to create or enable accounts, such as support_388945a0.

GroupAPT39

APT39 has created accounts on multiple compromised hosts to perform actions within the network.

GroupAPT41

APT41 has created user accounts.

GroupAPT5

APT5 has created Local Administrator accounts to maintain access to systems with short-cycle credential rotation.

GroupDaggerfly

Daggerfly created a local account on victim machines to maintain access.

GroupDragonfly

Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target.

GroupFIN13

FIN13 has created MS-SQL local accounts in a compromised network.

GroupFox Kitten

Fox Kitten has created a local user account with administrator privileges.

View all 14 groups examples

Software15

Used byProcedure example
MalwareCalisto

Calisto has the capability to add its own account to the victim's machine.

MalwareCarbanak

Carbanak can create a Windows account.

MalwareDarkGate

DarkGate creates a local user account, SafeMode, via net user commands.

ToolEmpire

Empire has a module for creating a local user if permissions allow.

MalwareFlame

Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available.

MalwareGoldenSpy

GoldenSpy can create new users on an infected system.

MalwareHiddenWasp

HiddenWasp creates a user account as a means to provide initial persistence to the compromised machine.

MalwareHildegard

Hildegard has created a user named “monerodaemon”.

View all 15 software examples

Campaigns1

Used byProcedure example
CampaignAnthropic AI-orchestrated Campaign

During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to create a local backdoor account to maintain access.

References3

  1. Cyber Security News Open source
    Kaaviya. (n.d.). SuperBlack Actors Exploiting Two Fortinet Vulnerabilities to Deploy Ransomware. Retrieved September 22, 2025.
  2. Kubernetes Service Accounts Security Open source
    Kubernetes. (n.d.). Service Accounts. Retrieved July 14, 2023.
  3. cisco_username_cmd Open source
    Cisco. (2023, March 6). username - Cisco IOS Security Command Reference: Commands S to Z. Retrieved July 13, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.