Sub-technique of T1136 Create Account.View on attack.mitre.org
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
For example, with a sufficient level of access, the Windows net user /add command can be used to create a local account. In Linux, the `useradd` command can be used, while on macOS systems, the dscl -create command can be used. Local accounts may also be added to network devices, often via common Network Device CLI commands such as username, to ESXi servers via `esxcli system account add`, or to Kubernetes clusters using the `kubectl` utility.
Adversaries may also create new local accounts on network firewall management consoles – for example, by exploiting a vulnerable firewall management system, threat actors may be able to establish super-admin accounts that could be used to modify firewall rules and gain further access to the network.
Such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
Rules on DetectionCode tagged with T1136.001.
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Cisco ASA - New Local User Account Created | Anomaly | NULL | Cisco ASA Logs |
| Create local admin accounts using net exe | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Detect New Local Admin account | TTP | NULL | Windows Event Log Security 4732, Windows Event Log Security 4720 |
| ESXi Account Modified | Anomaly | NULL | VMWare ESXi Syslog |
| Linux Add User Account | Hunting | NULL | Sysmon for Linux EventID 1, Cisco Isovalent Process Exec |
| Linux Auditd Add User Account | Anomaly | NULL | Linux Auditd Proctitle |
| Linux Auditd Add User Account Type | Anomaly | NULL | Linux Auditd Add User |
| Short Lived Windows Accounts | TTP | NULL | Windows Event Log System 4720, Windows Event Log System 4726 |
| Windows Create Local Account | Anomaly | NULL | Windows Event Log Security 4720 |
| Windows Create Local Administrator Account Via Net | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows ESX Admins Group Creation Security Event | TTP | NULL | Windows Event Log Security 4727, Windows Event Log Security 4730, Windows Event Log Security 4737 |
| Windows ESX Admins Group Creation via Net | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows ESX Admins Group Creation via PowerShell | TTP | NULL | Powershell Script Block Logging 4104 |
| Windows Privileged Group Modification | TTP | NULL | Windows Event Log Security 4727, Windows Event Log Security 4731, Windows Event Log Security 4744, Windows Event Log Security 4749, Windows Event Log Security 4754, Windows Event Log Security 4756, Windows Event Log Security 4759, Windows Event Log Security 4783, Windows Event Log Security 4790 |
| Used by | Procedure example |
|---|---|
| GroupAPT3 | APT3 has been known to create or enable accounts, such as |
| GroupAPT39 | APT39 has created accounts on multiple compromised hosts to perform actions within the network. |
| GroupAPT41 | APT41 has created user accounts. |
| GroupAPT5 | APT5 has created Local Administrator accounts to maintain access to systems with short-cycle credential rotation. |
| GroupDaggerfly | Daggerfly created a local account on victim machines to maintain access. |
| GroupDragonfly | Dragonfly has created accounts on victims, including administrator accounts, some of which appeared to be tailored to each individual staging target. |
| GroupFIN13 | FIN13 has created MS-SQL local accounts in a compromised network. |
| GroupFox Kitten | Fox Kitten has created a local user account with administrator privileges. |
| Used by | Procedure example |
|---|---|
| MalwareCalisto | Calisto has the capability to add its own account to the victim's machine. |
| MalwareCarbanak | Carbanak can create a Windows account. |
| MalwareDarkGate | DarkGate creates a local user account, |
| ToolEmpire | Empire has a module for creating a local user if permissions allow. |
| MalwareFlame | Flame can create backdoor accounts with login “HelpAssistant” on domain connected systems if appropriate rights are available. |
| MalwareGoldenSpy | GoldenSpy can create new users on an infected system. |
| MalwareHiddenWasp | HiddenWasp creates a user account as a means to provide initial persistence to the compromised machine. |
| MalwareHildegard | Hildegard has created a user named “monerodaemon”. |
| Used by | Procedure example |
|---|---|
| CampaignAnthropic AI-orchestrated Campaign | During the Anthropic AI-orchestrated Campaign, the adversary used Claude Code to create a local backdoor account to maintain access. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.