Create Account T1136
Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
Events covered
27 catalog events are tagged with this technique by at least one rule.
Authoring guide
Patterns shared across the 44 rules above: which fields they filter on, what specific values they look for, and what they exclude. The catalog normalizes field names across vendors so Sigma's Image, Elastic's process.name, and Splunk's process_name collapse into one row. Each rule contributes at most once per row.
Fields filtered most (36 distinct)
The fields most rules look at when detecting this technique. The How column shows the operators authors use (eq, wildcard, regex_match, match) and how often each appears. Sample values are concrete examples to start from, not an exhaustive list.
Top indicator values (151 distinct)
Specific (field, operator, value) combinations the rules check for, ranked by how many rules under this technique use each one. The Corpus reach column counts how many rules across the entire catalog (any technique) check the same combination. High numbers point to widely-used indicators that are likely noisy on their own; combine them with another condition for useful signal. Blank means the combination is specific to rules under this technique. Click a value to expand the rules under this technique that use it.
Exclusions (11 distinct)
Field/operator/value combinations excluded by rules under this technique (top-level not() clauses), sorted by how many rules exclude each. These are the false-positive paths the community has learned to filter out. A new rule that ignores the high-count entries here will likely fire on the same noisy paths. Click a value to expand the rules under this technique that exclude it.
Rules under this technique
Every rule in the catalog tagged with this technique, grouped by vendor. Click a rule title for its full predicates, exclusions, and indicators.
Sigma 20 rules
- Computer account created with privileges
- Creation of a Local Hidden User Account by Registry
- DarkGate - User Created Via Net.EXE
- Fortinet APT group abuse on Windows (user)
- Hidden account creation (with fast deletion)
- Hidden Local User Creation
- Local User Creation
- Manipulation of User Computer or Group Security Principals Across AD
- New User Created Via Net.EXE
- New User Created Via Net.EXE With Never Expire Option
- PowerShell Create Local User
- PSEXEC Remote Execution File Artefact
- Serv-U Exploitation CVE-2021-35211 by DEV-0322
- Suspicious computer account created by a computer account
- Suspicious Windows ANONYMOUS LOGON Local Account Created
- User account created by a computer account
- User account creation disguised in a computer account
- User Added to Remote Desktop Users Group
- User creation via commandline
- User enumeration and creation related to Manic Menagerie 2.0 (via cmdline)
Elastic 3 rules
- Creation of a Hidden Local User Account
- dMSA Account Creation by an Unusual User
- User Account Creation
Splunk 17 rules
- Create_Add Local_Domain User (EDR)
- Create_Add Local_Domain User (Sysmon)
- Create_Add Local_Domain User (Windows Event Log)
- Detect New Local Admin account
- Short Lived Windows Accounts
- User_Domain Enumeration Tool - Windows (PowerShell)
- User_Domain Enumeration Tool - Windows (Sysmon)
- User_Domain Enumeration Tool - Windows (Windows Event Log)
- Windows Azure PowerShell Module Installation Via PowerShell Script
- Windows Computer Account Changed to Domain Controller
- Windows Create Local Account
- Windows Create Local Administrator Account Via Net
- Windows Entra User Management Via Azure CLI
- Windows ESX Admins Group Creation Security Event
- Windows ESX Admins Group Creation via Net
- Windows ESX Admins Group Creation via PowerShell
- Windows Privileged Group Modification
Kusto 3 rules
- Account Creation
- Powershell Empire Cmdlets Executed in Command Line
- Unusual identity creation using exchange powershell