1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1136.001 Local Account — Detection Rules

Detection workspace for T1136.001 Local Account: 14 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0447 T1136.001 Detection Strategy - Local Account Creation Across Platforms

AN1235 Analytic 1235

Adversary uses built-in tools like 'net user /add', PowerShell, or WMI to create a local user. Sequence: Account creation event (4720) follows process creation of a suspicious executable (e.g., powershell.exe or net.exe).

AN1236 Analytic 1236

Local user accounts are created via binaries like 'useradd', 'adduser', or by editing passwd/shadow. Behavior chain includes execution of user management binaries or modification of user database files.

AN1237 Analytic 1237

Account creation using 'dscl -create' or via GUI tools. Detection involves command execution and file changes to the local directory services database.

AN1238 Analytic 1238

Account created using esxcli commands. Sequence includes esxcli execution and successful modification to account DB.

AN1239 Analytic 1239

Account created in a running container (e.g., via 'useradd' or by modifying /etc/passwd directly). Detectable via runtime telemetry (e.g., Falco or eBPF hooks).

AN1240 Analytic 1240

Account created via CLI using 'username' command or REST API. Detectable through AAA logging or CLI history telemetry.

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1136.001 simulation workspace

Threat actor context

These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.