New or Renamed User Account with '$' Character

 Original Source: [Sigma source]
Title: New or Renamed User Account with '$' Character
Status: test
Description:Detects the creation of a user with the "$" character. This can be used by attackers to hide a user or trick detection systems that lack the parsing mechanisms.
References:
  -https://twitter.com/SBousseaden/status/1387743867663958021
Author: Ilyas Ochkov, oscd.community
Date: 2019-10-25
modified:2024-01-16
Tags:
  • -'attack.stealth'
  • -'attack.t1036'
Logsource:
  • product: windows
  • service: security
Detection:
  selection_create:
    EventID: '4720'
    SamAccountName|contains: '$'
  selection_rename:
    EventID: '4781'
    NewTargetUserName|contains: '$'
  filter_main_homegroup:
    EventID: '4720'
    TargetUserName: 'HomeGroupUser$'
  condition:1 of selection_* and not 1 of filter_main_*
Falsepositives:
  -Unknown
Level: medium