Cross-source coverage

T1078.003 / ATT&CK

Valid Accounts: Local Accounts

25 rules across 4 sources.

From MITRE ATT&CK 19.2

Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.

Platforms
Containers · ESXi · Linux · macOS · Network Devices · Windows
Telemetry
WinEventLog:Securityauditd:USER_LOGINlinux:authmacos:unifiedlog

How MITRE says to detect it DET0407

Detection of Local Account Abuse for Initial Access and Persistence

Windows Analytic 1137

Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours.

  • WinEventLog:Security EventCode=4624, 4648
  • WinEventLog:Security EventCode=4672

Linux Analytic 1138

Detects interactive or service logins from local accounts outside expected operational context or at anomalous times.

  • auditd:USER_LOGIN USER_LOGIN
  • linux:auth sshd login

macOS Analytic 1139

Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH.

  • macos:unifiedlog loginwindow or sshd

elastic/detection-rules

13 rules
Detection Severity Format
Attempt to Enable the Root Account Medium Elastic TOML
Mounting Hidden or WebDav Remote Shares Medium Elastic TOML
Potential Admin Group Account Addition Medium Elastic TOML
Potential Hidden Local User Account Creation Medium Elastic TOML
Unusual Interactive Shell Launched from System User Medium Elastic TOML
Unusual Login via System User Medium Elastic TOML
Account Discovery Command via SYSTEM Account Low Elastic TOML
Potential Suspicious DebugFS Root Device Access Low Elastic TOML
Rare User Logon Low Elastic TOML
Spike in Successful Logon Events from a Source IP Low Elastic TOML

+ 3 more from elastic/detection-rules → showing the 10 highest-severity

SigmaHQ/sigma

5 rules
Detection Severity Format
Root Account Enable Via Dsenableroot Medium Sigma
User Added To Admin Group Via Dscl Medium Sigma
User Added To Admin Group Via DseditGroup Medium Sigma
User Added To Admin Group Via Sysadminctl Medium Sigma
Admin User Remote Logon Low Sigma

splunk/security_content

5 rules
Detection Severity Format
Cisco ASA - New Local User Account Created Undefined SPL
Cisco ASA - User Privilege Level Change Undefined SPL
Detect Excessive User Account Lockouts Undefined SPL
Potential password in username Undefined SPL
Short Lived Windows Accounts Undefined SPL

socfortress/Wazuh-Rules

2 rules
Detection Severity Format
Local account creation detected with password hash (useradd) High Wazuh XML
Password hash generation using openssl (passwd -1) detected — possible account creation preparation High Wazuh XML

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.