Cross-source coverage
T1078.003 / ATT&CK
Valid Accounts: Local Accounts
25 rules across 4 sources.
From MITRE ATT&CK 19.2
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.
- Tactics
- Stealth · Persistence · Privilege Escalation · Initial Access
- Platforms
- Containers · ESXi · Linux · macOS · Network Devices · Windows
- Telemetry
-
WinEventLog:Securityauditd:USER_LOGINlinux:authmacos:unifiedlog
How MITRE says to detect it DET0407
Detection of Local Account Abuse for Initial Access and Persistence
Windows Analytic 1137
Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours.
WinEventLog:SecurityEventCode=4624, 4648WinEventLog:SecurityEventCode=4672
Linux Analytic 1138
Detects interactive or service logins from local accounts outside expected operational context or at anomalous times.
auditd:USER_LOGINUSER_LOGINlinux:authsshd login
macOS Analytic 1139
Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH.
macos:unifiedlogloginwindow or sshd
elastic/detection-rules
13 rules| Detection | Severity | Format |
|---|---|---|
| Attempt to Enable the Root Account | Medium | Elastic TOML |
| Mounting Hidden or WebDav Remote Shares | Medium | Elastic TOML |
| Potential Admin Group Account Addition | Medium | Elastic TOML |
| Potential Hidden Local User Account Creation | Medium | Elastic TOML |
| Unusual Interactive Shell Launched from System User | Medium | Elastic TOML |
| Unusual Login via System User | Medium | Elastic TOML |
| Account Discovery Command via SYSTEM Account | Low | Elastic TOML |
| Potential Suspicious DebugFS Root Device Access | Low | Elastic TOML |
| Rare User Logon | Low | Elastic TOML |
| Spike in Successful Logon Events from a Source IP | Low | Elastic TOML |
+ 3 more from elastic/detection-rules → showing the 10 highest-severity
SigmaHQ/sigma
5 rules| Detection | Severity | Format |
|---|---|---|
| Root Account Enable Via Dsenableroot | Medium | Sigma |
| User Added To Admin Group Via Dscl | Medium | Sigma |
| User Added To Admin Group Via DseditGroup | Medium | Sigma |
| User Added To Admin Group Via Sysadminctl | Medium | Sigma |
| Admin User Remote Logon | Low | Sigma |
splunk/security_content
5 rules| Detection | Severity | Format |
|---|---|---|
| Cisco ASA - New Local User Account Created | Undefined | SPL |
| Cisco ASA - User Privilege Level Change | Undefined | SPL |
| Detect Excessive User Account Lockouts | Undefined | SPL |
| Potential password in username | Undefined | SPL |
| Short Lived Windows Accounts | Undefined | SPL |
socfortress/Wazuh-Rules
2 rules| Detection | Severity | Format |
|---|---|---|
| Local account creation detected with password hash (useradd) | High | Wazuh XML |
| Password hash generation using openssl (passwd -1) detected — possible account creation preparation | High | Wazuh XML |