1200KM / detection
T1136.001 Local Account — Detection Rules
Detection workspace for T1136.001 Local Account: 14 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Creation Of An User Account · test · medium · {"product":"linux","service":"auditd"}
- Privileged User Has Been Created · test · high · {"product":"linux","definition":"/var/log/secure on REHL systems or /var/log/auth.log on debian like Systems needs to be collected in order for this detection to work"}
- Creation Of A Local User Account · test · low · {"category":"process_creation","product":"macos"}
- Cisco Local Accounts · test · high · {"product":"cisco","service":"aaa"}
- FortiGate - New Administrator Account Created · experimental · medium · {"product":"fortigate","service":"event"}
- FortiGate - New Local User Created · experimental · medium · {"product":"fortigate","service":"event"}
- Hidden Local User Creation · test · high · {"product":"windows","service":"security"}
- Suspicious Windows ANONYMOUS LOGON Local Account Created · test · high · {"product":"windows","service":"security"}
- Local User Creation · test · low · {"product":"windows","service":"security"}
- PowerShell Create Local User · test · medium · {"product":"windows","category":"ps_script","definition":"Requirements: Script Block Logging must be enabled"}
- New User Created Via Net.EXE · test · medium · {"category":"process_creation","product":"windows"}
- New User Created Via Net.EXE With Never Expire Option · test · high · {"category":"process_creation","product":"windows"}
- User Added to Remote Desktop Users Group · test · high · {"category":"process_creation","product":"windows"}
- Creation of a Local Hidden User Account by Registry · test · high · {"product":"windows","category":"registry_event"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0447 T1136.001 Detection Strategy - Local Account Creation Across Platforms
AN1235 Analytic 1235
Adversary uses built-in tools like 'net user /add', PowerShell, or WMI to create a local user. Sequence: Account creation event (4720) follows process creation of a suspicious executable (e.g., powershell.exe or net.exe).
AN1236 Analytic 1236
Local user accounts are created via binaries like 'useradd', 'adduser', or by editing passwd/shadow. Behavior chain includes execution of user management binaries or modification of user database files.
AN1237 Analytic 1237
Account creation using 'dscl -create' or via GUI tools. Detection involves command execution and file changes to the local directory services database.
AN1238 Analytic 1238
Account created using esxcli commands. Sequence includes esxcli execution and successful modification to account DB.
AN1239 Analytic 1239
Account created in a running container (e.g., via 'useradd' or by modifying /etc/passwd directly). Detectable via runtime telemetry (e.g., Falco or eBPF hooks).
AN1240 Analytic 1240
Account created via CLI using 'username' command or REST API. Detectable through AAA logging or CLI history telemetry.
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.