Create Account

T1136

Technique with 3 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.

Accounts may be created on the local system or within a domain or cloud tenant. In cloud environments, adversaries may create accounts that only have access to specific services, which can reduce the chance of detection.

Detection rules64

Rules on DetectionCode tagged with T1136 or one of its sub-techniques.

Sigma23

RuleLevelLog sourceTechnique
Cisco Local Accountshighcisco / NULLT1136.001
Creation of a Local Hidden User Account by Registryhighwindows / registry_eventT1136.001
Hidden Local User Creationhighwindows / NULLT1136.001
New User Created Via Net.EXE With Never Expire Optionhighwindows / process_creationT1136.001
Privileged User Has Been Createdhighlinux / NULLT1136.001
PSEXEC Remote Execution File Artefacthighwindows / file_eventT1136.002
Suspicious Windows ANONYMOUS LOGON Local Account Createdhighwindows / NULLT1136.001 T1136.002
User Added to Remote Desktop Users Grouphighwindows / process_creationT1136.001
Creation Of An User Accountmediumlinux / NULLT1136.001
ESXi Account Creation Via ESXCLImediumlinux / process_creationT1136
FortiGate - New Administrator Account Createdmediumfortigate / NULLT1136.001
FortiGate - New Local User Createdmediumfortigate / NULLT1136.001
Manipulation of User Computer or Group Security Principals Across ADmediumwindows / ps_scriptT1136.002
New Federated Domain Added - Exchangemediumm365 / NULLT1136.003
New User Account Creation Attempt Via ADSImediumwindows / ps_scriptT1136.001 T1136.002

Splunk41

RuleTypeRiskData sourceTechnique
ASL AWS Create Access KeyHuntingNULLASL AWS CloudTrailT1136.003
ASL AWS UpdateLoginProfileTTPNULLASL AWS CloudTrailT1136.003
AWS CreateAccessKeyHuntingNULLAWS CloudTrail CreateAccessKeyT1136.003
AWS CreateLoginProfileTTPNULLAWS CloudTrail CreateLoginProfile AND AWS CloudTrail ConsoleLoginT1136.003
AWS UpdateLoginProfileTTPNULLAWS CloudTrail UpdateLoginProfileT1136.003
Azure AD External Guest User InvitedTTPNULLAzure Active Directory Invite external userT1136.003
Azure AD Multiple Service Principals Created by SPAnomalyNULLAzure Active Directory Add service principalT1136.003
Azure AD Multiple Service Principals Created by UserAnomalyNULLAzure Active Directory Add service principalT1136.003
Azure AD Service Principal CreatedTTPNULLAzure Active Directory Add service principalT1136.003
Azure Automation Account CreatedTTPNULLAzure Audit Create or Update an Azure Automation accountT1136.003
Azure Automation Runbook CreatedTTPNULLAzure Audit Create or Update an Azure Automation RunbookT1136.003
Cisco ASA - New Local User Account CreatedAnomalyNULLCisco ASA LogsT1136.001
Cisco IOS Suspicious Privileged Account CreationAnomalyNULLCisco IOS LogsT1136
Cisco Privileged Account Creation with HTTP Command ExecutionCorrelationNULLT1136
Cisco Privileged Account Creation with Suspicious SSH ActivityCorrelationNULLT1136

Sub-techniques3

IDNameExamples
T1136.001Local Account30
T1136.002Domain Account11
T1136.003Cloud Account3

Groups3

Software1

Campaigns1

Procedure examples5

Groups3

Used byProcedure example
GroupIndrik Spider

Indrik Spider used wmic.exe to add a new user to the system.

GroupSalt Typhoon

Salt Typhoon has created Linux-level users on compromised network devices through modification of `/etc/shadow` and `/etc/passwd`.

GroupScattered Spider

Scattered Spider creates new user identities within the compromised organization.

Software1

Used byProcedure example
MalwareLockBit 2.0

LockBit 2.0 has been observed creating accounts for persistence using simple names like "a".

Campaigns1

Used byProcedure example
Campaign2016 Ukraine Electric Power Attack

During the 2016 Ukraine Electric Power Attack, Sandworm Team added a login to a SQL Server with `sp_addlinkedsrvlogin`.

References1

  1. Symantec WastedLocker June 2020 Open source
    Symantec Threat Intelligence. (2020, June 25). WastedLocker: Symantec Identifies Wave of Attacks Against U.S. Organizations. Retrieved May 20, 2021.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.