Create Account T1136
Tactic: Persistence
Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
Events covered
33 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 165 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (152 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (633 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (68 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 38 rules
- AWS ElastiCache Security Group Created
- Cisco Local Accounts
- Computer account created with privileges
- Creation of a Local Hidden User Account by Registry
- Creation Of A Local User Account
- Creation Of An User Account
- DarkGate - User Created Via Net.EXE
- ESXi Account Creation Via ESXCLI
- FortiGate - New Administrator Account Created
- FortiGate - New Local User Created
- Fortinet APT group abuse on Windows (user)
- Hidden account creation (with fast deletion)
- Hidden Local User Creation
- IAM User Created
- IAM User Creation Attempt
- Local User Creation
- macOS User Account Manipulation
- Manipulation of User Computer or Group Security Principals Across AD
- New Federated Domain Added - Exchange
- New Github Organization Member Added
- New Kubernetes Service Account Created
- New User Created Via Net.EXE
- New User Created Via Net.EXE With Never Expire Option
- PowerShell Create Local User
- Privileged User Has Been Created
- PSEXEC Remote Execution File Artefact
- Risk of signup fraud - rapid creation of fake accounts
- Risk of signup fraud - rapid creation of fake accounts with disposable email domains
- Risk of Tenant Takeover
- Serv-U Exploitation CVE-2021-35211 by DEV-0322
- SQL SA admin user enabled
- Suspicious computer account created by a computer account
- Suspicious Windows ANONYMOUS LOGON Local Account Created
- User account created by a computer account
- User account creation disguised in a computer account
- User Added to Remote Desktop Users Group
- User creation via commandline
- User enumeration and creation related to Manic Menagerie 2.0 (via cmdline)
Elastic 24 rules
- Attempt to Create Okta API Token
- AWS IAM Create User via Assumed Role on EC2 Instance
- AWS IAM Group Creation
- AWS IAM Sensitive Operations via Lambda Execution Role
- AWS Sensitive IAM Operations Performed via CloudShell
- Creation of a Hidden Local User Account
- dMSA Account Creation by an Unusual User
- Entra ID External Guest User Invited
- Entra ID Service Principal Created
- GCP Service Account Creation
- Linux Group Creation
- Linux User Account Creation
- Linux User Added to Privileged Group
- New GitHub Owner Added
- New GitHub Personal Access Token (PAT) Added
- OpenSSL Password Hash Generation
- Potential Hidden Local User Account Creation
- Potential Linux Backdoor User Account Creation
- Potential Persistence via File Modification
- Shadow File Modification by Unusual Process
- Spike in User Account Management Events
- Suspicious Passwd File Event Action
- User Account Creation
- User or Group Creation/Modification
Splunk 45 rules
- ASL AWS Create Access Key
- ASL AWS UpdateLoginProfile
- AWS CreateAccessKey
- AWS CreateLoginProfile
- AWS UpdateLoginProfile
- Azure AD External Guest User Invited
- Azure AD Multiple Service Principals Created by SP
- Azure AD Multiple Service Principals Created by User
- Azure AD Service Principal Created
- Azure Automation Account Created
- Azure Automation Runbook Created
- Cisco ASA - New Local User Account Created
- Cisco IOS Suspicious Privileged Account Creation
- Cisco Privileged Account Creation with HTTP Command Execution
- Cisco Privileged Account Creation with Suspicious SSH Activity
- Create_Add Local_Domain User (EDR)
- Create_Add Local_Domain User (Sysmon)
- Create_Add Local_Domain User (Windows Event Log)
- Detect New Local Admin account
- ESXi Account Modified
- Linux Add User Account
- Linux Auditd Add User Account
- Linux Auditd Add User Account Type
- MacOS Account Created
- O365 Add App Role Assignment Grant User
- O365 Added Service Principal
- O365 External Guest User Invited
- O365 External Identity Policy Changed
- O365 Multiple Service Principals Created by SP
- O365 Multiple Service Principals Created by User
- O365 New Federated Domain Added
- O365 SharePoint Allowed Domains Policy Changed
- Short Lived Windows Accounts
- User_Domain Enumeration Tool - Windows (PowerShell)
- User_Domain Enumeration Tool - Windows (Sysmon)
- User_Domain Enumeration Tool - Windows (Windows Event Log)
- Windows Azure PowerShell Module Installation Via PowerShell Script
- Windows Computer Account Changed to Domain Controller
- Windows Create Local Account
- Windows Create Local Administrator Account Via Net
- Windows Entra User Management Via Azure CLI
- Windows ESX Admins Group Creation Security Event
- Windows ESX Admins Group Creation via Net
- Windows ESX Admins Group Creation via PowerShell
- Windows Privileged Group Modification
Kusto 22 rules
- Account created from non-approved sources
- Account Creation
- Anomalous login followed by Teams action
- Cross-tenant Access Settings Organization Added
- Cross-tenant Access Settings Organization Deleted
- Cross-tenant Access Settings Organization Inbound Collaboration Settings Changed
- Cross-tenant Access Settings Organization Inbound Direct Settings Changed
- Cross-tenant Access Settings Organization Outbound Collaboration Settings Changed
- Cross-tenant Access Settings Organization Outbound Direct Settings Changed
- External guest invitation followed by Microsoft Entra ID PowerShell signin
- External user added and removed in short timeframe
- F&O - Non-interactive account mapped to self or sensitive privileged user
- GCP IAM - New Service Account
- GitLab - External User Added to GitLab
- Guest accounts added in Entra ID Groups other than the ones specified
- Pathlock TDnR - SAP Cloud Account Administration Events
- Ping Federate - New user SSO success login
- Powershell Empire Cmdlets Executed in Command Line
- Rare application consent
- Unusual identity creation using exchange powershell
- User Account Created Using Incorrect Naming Format
- User account created without expected attributes defined
YARA-L 7 rules
- AWS Privilege Escalation Using IAM Access Key
- AWS Privilege Escalation Using IAM Login Profile
- GCP Free Gmail Domains Added To IAM Policy
- New User Created Via Net.EXE
- sap hanadb user admin actions
- sap security audit log user created deleted or unlocked
- sap user creates and uses new user
Panther 29 rules
- AppOmni Alert Passthrough
- Auth0 Fraud Risk by Volume
- Auth0 New Admin Invited
- Auth0 New Admin Invited FOLLOWED BY Tenant Member Account Deletion
- Auth0 Rapid Dynamic Client Creation
- Carbon Black API Key Created or Retrieved
- Carbon Black User Added Outside Org
- Crowdstrike Ephemeral User Account
- Crowdstrike New Admin User Created
- Crowdstrike New User Created
- Databricks Account Admin Privileged Role Assignment
- Databricks Group Created
- Databricks User Account Created
- Databricks Workspace Admin Privileged Role Assignment
- GCP Corporate Email Not Used
- GCP Inbound SSO Profile Created
- GCP Workforce Pool Created or Updated
- GCP Workload Identity Pool Created or Updated
- IAM Entity Created Without CloudFormation
- New AWS Account Created
- New User Account Created
- Slack Organization Created
- Snowflake User Created
- Snowflake User Created
- Snowflake User Enabled
- Snowflake User Enabled
- Teleport Create User Accounts
- Wiz User Created Or Deleted
- ZIA Cloud Account Created