1200KM / simulation
T1136.001 Local Account — Attack Simulation
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. For example, with a sufficient level of access, the Windows net user /add command can be used to create a local account. In Linux, the `useradd` command can be used, while on macOS systems, the dscl -create command can…
Technique description
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. For example, with a sufficient level of access, the Windows net user /add command can be used to create a local account. In Linux, the `useradd` command can be used, while on macOS systems, the dscl -create command can…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Create a user account on a MacOS system
Procedure 01993ba5-1da3-4e15-a719-b690d4f0f0b2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create a new Windows admin user via .NET
Procedure 2170d9b5-bacd-4819-a952-da76dae0815f; elevation required; cleanup not declared. Not executed or individually validated.
- Create a user account on a Linux system
Procedure 40d8eabd-e394-46f6-8785-b9bfa1d011d2; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create a new user in a command prompt
Procedure 6657864e-0323-4206-9344-ac9cd7265a4f; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create a new user in Linux with `root` UID and GID.
Procedure a1040a30-d28b-4eda-bd99-bb2861a4616c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create a user account on a FreeBSD system
Procedure a39ee1bc-b8c1-4331-8e5f-1859eb408518; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create a new user in PowerShell
Procedure bc8be0ac-475c-4fbf-9b1d-9fffd77afbde; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create a new user in FreeBSD with `root` GID.
Procedure d141afeb-d2bc-4934-8dd5-b7dba0f9f67a; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Create a Linux user via kubectl in a Pod
Procedure d9efa6c7-6518-42b2-809a-4f2a8e242b9b; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Create a new Windows admin user
Procedure fda74566-a604-4581-a4cc-fbbe21d66559; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.