Create Account: Local Account T1136.001
Tactic: Persistence
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Events covered
24 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 49 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (44 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (335 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (38 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 19 rules
- Cisco Local Accounts
- Creation of a Local Hidden User Account by Registry
- Creation Of A Local User Account
- Creation Of An User Account
- DarkGate - User Created Via Net.EXE
- FortiGate - New Administrator Account Created
- FortiGate - New Local User Created
- Hidden Local User Creation
- Local User Creation
- macOS User Account Manipulation
- New User Created Via Net.EXE
- New User Created Via Net.EXE With Never Expire Option
- PowerShell Create Local User
- Privileged User Has Been Created
- Serv-U Exploitation CVE-2021-35211 by DEV-0322
- Suspicious Windows ANONYMOUS LOGON Local Account Created
- User Added to Remote Desktop Users Group
- User creation via commandline
- User enumeration and creation related to Manic Menagerie 2.0 (via cmdline)
Elastic 12 rules
- Creation of a Hidden Local User Account
- Linux Group Creation
- Linux User Account Creation
- Linux User Added to Privileged Group
- OpenSSL Password Hash Generation
- Potential Hidden Local User Account Creation
- Potential Linux Backdoor User Account Creation
- Potential Persistence via File Modification
- Shadow File Modification by Unusual Process
- Suspicious Passwd File Event Action
- User Account Creation
- User or Group Creation/Modification
Splunk 16 rules
- Cisco ASA - New Local User Account Created
- Create_Add Local_Domain User (EDR)
- Create_Add Local_Domain User (Sysmon)
- Create_Add Local_Domain User (Windows Event Log)
- Detect New Local Admin account
- ESXi Account Modified
- Linux Add User Account
- Linux Auditd Add User Account
- Linux Auditd Add User Account Type
- Short Lived Windows Accounts
- Windows Create Local Account
- Windows Create Local Administrator Account Via Net
- Windows ESX Admins Group Creation Security Event
- Windows ESX Admins Group Creation via Net
- Windows ESX Admins Group Creation via PowerShell
- Windows Privileged Group Modification