1200KM / simulation
T1078.003 Local Accounts — Attack Simulation
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the…
Technique description
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Create local account (Linux)
Procedure 02a91c34-8a5b-4bed-87af-501103eb5357; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Reactivate a locked/expired account (FreeBSD)
Procedure 09e3380a-fae5-4255-8b19-9950be0252cf; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Login as nobody (freebsd)
Procedure 16f6374f-7600-459a-9b16-6a88fd96d310; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create local account with admin privileges using sysadminctl utility - MacOS
Procedure 191db57d-091a-47d5-99f3-97fde53de505; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Enable root account using dsenableroot utility - MacOS
Procedure 20b40ea9-0e17-4155-b8e6-244911a678ac; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Login as nobody (Linux)
Procedure 3d2cd093-ee05-41bd-a802-59ee5c301b85; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Add a new/existing user to the admin group using dseditgroup utility - macOS
Procedure 433842ba-e796-4fd5-a14f-95d3a1970875; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Use PsExec to elevate to NT Authority\SYSTEM account
Procedure 6904235f-0f55-4039-8aed-41c300ff7733; elevation required; cleanup not declared. Not executed or individually validated.
- WinPwn - Loot local Credentials - powerhell kittie
Procedure 9e9fd066-453d-442f-88c1-ad7911d32912; elevation required; cleanup not declared. Not executed or individually validated.
- Create local account with admin privileges
Procedure a524ce99-86de-4db6-b4f9-e08f35a47a15; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Reactivate a locked/expired account (Linux)
Procedure d2b95631-62d7-45a3-aaef-0972cea97931; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- WinPwn - Loot local Credentials - Safetykatz
Procedure e9fdb899-a980-4ba4-934b-486ad22e22f4; elevation required; cleanup not declared. Not executed or individually validated.
- Create local account with admin privileges - MacOS
Procedure f1275566-1c26-4b66-83e3-7f9f7f964daa; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.