EXPLORE
← Back to Explore
T1136

Create Account

Adversaries may create an account to maintain access to victim systems.(Citation: Symantec WastedLocker June 2020) With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system. Accounts may be created on the local system or within a domain or cloud tenant. In cloud environments, adversaries may create accounts that only have access to specific services, which can r...

WindowsIaaSLinuxmacOSNetwork DevicesContainersSaaSOffice SuiteIdentity ProviderESXi
38
Detections
4
Sources
3
Threat Actors

BY SOURCE

27elastic5splunk_escu3kql3sigma

PROCEDURES (27)

Persist4 detections

Auto-extracted: 4 detections for persist

Persist3 detections

Auto-extracted: 3 detections for persist

Process Creation Monitoring2 detections

Auto-extracted: 2 detections for process creation monitoring

Credential2 detections

Auto-extracted: 2 detections for credential

Service2 detections

Auto-extracted: 2 detections for service

Bypass2 detections

Auto-extracted: 2 detections for bypass

Privilege2 detections

Auto-extracted: 2 detections for privilege

Unusual1 detections

Auto-extracted: 1 detections for unusual

C21 detections

Auto-extracted: 1 detections for c2

Token1 detections

Auto-extracted: 1 detections for token

Persist1 detections

Auto-extracted: 1 detections for persist

Persist1 detections

Auto-extracted: 1 detections for persist

Registry Monitoring1 detections

Auto-extracted: 1 detections for registry monitoring

Unusual1 detections

Auto-extracted: 1 detections for unusual

Cloud1 detections

Auto-extracted: 1 detections for cloud

Bypass1 detections

Auto-extracted: 1 detections for bypass

Api1 detections

Auto-extracted: 1 detections for api

Cloud Monitoring1 detections

Auto-extracted: 1 detections for cloud monitoring

General Monitoring1 detections

Auto-extracted: 1 detections for general monitoring

Token1 detections

Auto-extracted: 1 detections for token

Privilege1 detections

Auto-extracted: 1 detections for privilege

Unusual1 detections

Auto-extracted: 1 detections for unusual

Privilege1 detections

Auto-extracted: 1 detections for privilege

C21 detections

Auto-extracted: 1 detections for c2

Service1 detections

Auto-extracted: 1 detections for service

Azure1 detections

Auto-extracted: 1 detections for azure

Unusual1 detections

Auto-extracted: 1 detections for unusual

DETECTIONS (38)

Attempt to Create Okta API Token
elasticmedium
AWS ElastiCache Security Group Created
sigmalow
AWS IAM Create User via Assumed Role on EC2 Instance
elasticmedium
AWS IAM Group Creation
elasticlow
AWS IAM Sensitive Operations via Lambda Execution Role
elastichigh
AWS Sensitive IAM Operations Performed via CloudShell
elasticmedium
Cisco IOS Suspicious Privileged Account Creation
splunk_escu
Cisco Privileged Account Creation with HTTP Command Execution
splunk_escu
Cisco Privileged Account Creation with Suspicious SSH Activity
splunk_escu
Cloud Persistence Activities by User At Risk
kql
Commandline User Addition
kql
Creation of a Hidden Local User Account
elastichigh
dMSA Account Creation by an Unusual User
elastichigh
Entra ID External Guest User Invited
elasticlow
Entra ID Service Principal Created
elasticlow
ESXi Account Creation Via ESXCLI
sigmamedium
FortiGate Administrator Account Creation from Unusual Source
elasticmedium
FortiGate SSO Login Followed by Administrator Account Creation
elastichigh
FortiGate Super Admin Account Creation
elasticmedium
GCP Service Account Creation
elasticlow
Linux Group Creation
elasticlow
Linux User Account Creation
elasticlow
Linux User Added to Privileged Group
elasticlow
Local Administrator Additions
kql
MacOS Account Created
splunk_escu
New GitHub Owner Added
elasticmedium
New GitHub Personal Access Token (PAT) Added
elasticlow
New Kubernetes Service Account Created
sigmalow
OpenSSL Password Hash Generation
elasticmedium
Potential Hidden Local User Account Creation
elasticmedium
Potential Linux Backdoor User Account Creation
elastichigh
Potential Persistence via File Modification
elasticlow
Shadow File Modification by Unusual Process
elasticlow
Spike in User Account Management Events
elasticlow
Suspicious Passwd File Event Action
elasticmedium
User Account Creation
elasticlow
User or Group Creation/Modification
elasticlow
Windows Entra User Management Via Azure CLI
splunk_escu