Technique with 3 sub-techniques.View on attack.mitre.org
Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
Accounts may be created on the local system or within a domain or cloud tenant. In cloud environments, adversaries may create accounts that only have access to specific services, which can reduce the chance of detection.
Rules on DetectionCode tagged with T1136 or one of its sub-techniques.
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| ASL AWS Create Access Key | Hunting | NULL | ASL AWS CloudTrail | T1136.003 |
| ASL AWS UpdateLoginProfile | TTP | NULL | ASL AWS CloudTrail | T1136.003 |
| AWS CreateAccessKey | Hunting | NULL | AWS CloudTrail CreateAccessKey | T1136.003 |
| AWS CreateLoginProfile | TTP | NULL | AWS CloudTrail CreateLoginProfile AND AWS CloudTrail ConsoleLogin | T1136.003 |
| AWS UpdateLoginProfile | TTP | NULL | AWS CloudTrail UpdateLoginProfile | T1136.003 |
| Azure AD External Guest User Invited | TTP | NULL | Azure Active Directory Invite external user | T1136.003 |
| Azure AD Multiple Service Principals Created by SP | Anomaly | NULL | Azure Active Directory Add service principal | T1136.003 |
| Azure AD Multiple Service Principals Created by User | Anomaly | NULL | Azure Active Directory Add service principal | T1136.003 |
| Azure AD Service Principal Created | TTP | NULL | Azure Active Directory Add service principal | T1136.003 |
| Azure Automation Account Created | TTP | NULL | Azure Audit Create or Update an Azure Automation account | T1136.003 |
| Azure Automation Runbook Created | TTP | NULL | Azure Audit Create or Update an Azure Automation Runbook | T1136.003 |
| Cisco ASA - New Local User Account Created | Anomaly | NULL | Cisco ASA Logs | T1136.001 |
| Cisco IOS Suspicious Privileged Account Creation | Anomaly | NULL | Cisco IOS Logs | T1136 |
| Cisco Privileged Account Creation with HTTP Command Execution | Correlation | NULL | T1136 | |
| Cisco Privileged Account Creation with Suspicious SSH Activity | Correlation | NULL | T1136 | |
| Create local admin accounts using net exe | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1136.001 |
| Detect New Local Admin account | TTP | NULL | Windows Event Log Security 4732, Windows Event Log Security 4720 | T1136.001 |
| ESXi Account Modified | Anomaly | NULL | VMWare ESXi Syslog | T1136.001 |
| Linux Add User Account | Hunting | NULL | Sysmon for Linux EventID 1, Cisco Isovalent Process Exec | T1136.001 |
| Linux Auditd Add User Account | Anomaly | NULL | Linux Auditd Proctitle | T1136.001 |
| Linux Auditd Add User Account Type | Anomaly | NULL | Linux Auditd Add User | T1136.001 |
| MacOS Account Created | Anomaly | NULL | Osquery Results | T1136 |
| O365 Add App Role Assignment Grant User | TTP | NULL | O365 Add app role assignment grant to user. | T1136.003 |
| O365 Added Service Principal | TTP | NULL | O365 | T1136.003 |
| O365 External Guest User Invited | TTP | NULL | Office 365 Universal Audit Log | T1136.003 |
| O365 External Identity Policy Changed | TTP | NULL | Office 365 Universal Audit Log | T1136.003 |
| O365 Multiple Service Principals Created by SP | Anomaly | NULL | O365 Add service principal. | T1136.003 |
| O365 Multiple Service Principals Created by User | Anomaly | NULL | O365 Add service principal. | T1136.003 |
| O365 New Federated Domain Added | TTP | NULL | O365 | T1136.003 |
| O365 SharePoint Allowed Domains Policy Changed | TTP | NULL | Office 365 Universal Audit Log | T1136.003 |
| Short Lived Windows Accounts | TTP | NULL | Windows Event Log System 4720, Windows Event Log System 4726 | T1136.001 |
| Web Fraud - Account Harvesting | TTP | NULL | T1136 | |
| Windows Azure PowerShell Module Installation Via PowerShell Script | Anomaly | NULL | Powershell Script Block Logging 4104 | T1136.003 |
| Windows Computer Account Changed to Domain Controller | TTP | NULL | Windows Event Log Security 4742 | T1136.002 |
| Windows Create Local Account | Anomaly | NULL | Windows Event Log Security 4720 | T1136.001 |
| Windows Create Local Administrator Account Via Net | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1136.001 |
| Windows Entra User Management Via Azure CLI | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1136 |
| Windows ESX Admins Group Creation Security Event | TTP | NULL | Windows Event Log Security 4727, Windows Event Log Security 4730, Windows Event Log Security 4737 | T1136.001 T1136.002 |
| Windows ESX Admins Group Creation via Net | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1136.001 T1136.002 |
| Windows ESX Admins Group Creation via PowerShell | TTP | NULL | Powershell Script Block Logging 4104 | T1136.001 T1136.002 |
| Windows Privileged Group Modification | TTP | NULL | Windows Event Log Security 4727, Windows Event Log Security 4731, Windows Event Log Security 4744, Windows Event Log Security 4749, Windows Event Log Security 4754, Windows Event Log Security 4756, Windows Event Log Security 4759, Windows Event Log Security 4783, Windows Event Log Security 4790 | T1136.001 T1136.002 |
| Used by | Procedure example |
|---|---|
| GroupIndrik Spider | Indrik Spider used |
| GroupSalt Typhoon | Salt Typhoon has created Linux-level users on compromised network devices through modification of `/etc/shadow` and `/etc/passwd`. |
| GroupScattered Spider | Scattered Spider creates new user identities within the compromised organization. |
| Used by | Procedure example |
|---|---|
| MalwareLockBit 2.0 | LockBit 2.0 has been observed creating accounts for persistence using simple names like "a". |
| Used by | Procedure example |
|---|---|
| Campaign2016 Ukraine Electric Power Attack | During the 2016 Ukraine Electric Power Attack, Sandworm Team added a login to a SQL Server with `sp_addlinkedsrvlogin`. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.