1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1078.003 Local Accounts — Detection Rules

Detection workspace for T1078.003 Local Accounts: 5 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0407 Detection of Local Account Abuse for Initial Access and Persistence

AN1137 Analytic 1137

Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours.

AN1138 Analytic 1138

Detects interactive or service logins from local accounts outside expected operational context or at anomalous times.

AN1139 Analytic 1139

Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1078.003 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.