{"id":"T1036.010","name":"Masquerade Account Name","url":"https://attack.mitre.org/techniques/T1036/010","tactics":["stealth"],"platforms":["Containers","IaaS","Identity Provider","Linux","macOS","Office Suite","SaaS","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0383","stix_id":"x-mitre-detection-strategy--f1f9b6fc-a261-4bcf-a0c0-3ae42cdc28fc","name":"Detection Strategy for Masquerading via Account Name Similarity","url":"https://attack.mitre.org/detectionstrategies/DET0383","analytics":[{"id":"AN1077","stix_id":"x-mitre-analytic--8c3a43bc-dd07-4e72-a987-a2dc36e162fa","name":"Analytic 1077","description":"Detects adversary behavior where a newly created or renamed user account closely resembles existing service or administrator accounts to blend in and avoid detection. Common patterns include prefix/suffix modifications, homoglyphs, or use of names like 'admin1', 'adm1n', or 'backup_help'.","url":"https://attack.mitre.org/detectionstrategies/DET0383#AN1077","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4720","data_component":"DC0014","data_component_name":"User Account Creation","log_source_slug":"wineventlog-security"},{"name":"windows:osquery","channel":"User enumeration with creation/last modified timestamps","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"windows-osquery"}],"mutable_elements":[{"field":"SimilarityThreshold","description":"Defines how close in Levenshtein or visual distance an account name must be to a legitimate one to raise an alert."},{"field":"MonitoredAccountList","description":"Set of known legitimate accounts to compare new account names against."},{"field":"TimeWindow","description":"Period within which anomalous account creation or renaming is evaluated in relation to discovery or deletion activity."}],"live":true,"detection_strategies":["DET0383"],"techniques":["T1036.010"]},{"id":"AN1078","stix_id":"x-mitre-analytic--5f584d00-63b5-44c5-b629-ff238f5b9931","name":"Analytic 1078","description":"Detects creation or renaming of accounts with names that closely match known service, root, or admin accounts. Behavior often follows account discovery or deletion, attempting to blend into system activity logs using trusted name conventions.","url":"https://attack.mitre.org/detectionstrategies/DET0383#AN1078","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"adduser","data_component":"DC0014","data_component_name":"User Account Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"usermod, or account rename system calls","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"auditd-syscall"},{"name":"linux:osquery","channel":"Listing of /etc/passwd and /etc/shadow metadata","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"linux-osquery"}],"mutable_elements":[{"field":"AllowedSystemAccounts","description":"Whitelist of legitimate service accounts used for validation."},{"field":"LevenshteinThreshold","description":"Edit distance sensitivity between created account and existing account names."},{"field":"ScriptInitiatorDetection","description":"Whether to flag account creation events triggered from suspicious scripts or shell histories."}],"live":true,"detection_strategies":["DET0383"],"techniques":["T1036.010"]},{"id":"AN1079","stix_id":"x-mitre-analytic--0252a0ff-a4fb-4196-9b43-d759af950d55","name":"Analytic 1079","description":"Detects adversary creation of cloud or IdP accounts whose names resemble existing privileged or service accounts. May indicate preparation for privilege escalation or defense evasion.","url":"https://attack.mitre.org/detectionstrategies/DET0383#AN1079","platforms":["Identity Provider"],"log_source_references":[{"name":"azure:audit","channel":"Add user","data_component":"DC0014","data_component_name":"User Account Creation","log_source_slug":"azure-audit"},{"name":"azure:audit","channel":"Rename user","data_component":"DC0010","data_component_name":"User Account Modification","log_source_slug":"azure-audit"},{"name":"saas:okta","channel":"User lifecycle events","data_component":"DC0013","data_component_name":"User Account Metadata","log_source_slug":"saas-okta"}],"mutable_elements":[{"field":"RoleScope","description":"Whether created users have privileged or scoped roles assigned at creation."},{"field":"NamingHeuristics","description":"Regex patterns or heuristics for detecting suspicious naming conventions (e.g., helpdesk_support_, root-admin)."}],"live":true,"detection_strategies":["DET0383"],"techniques":["T1036.010"]},{"id":"AN1080","stix_id":"x-mitre-analytic--fb767270-25ad-4fea-a8e7-8f9c57ac1fa8","name":"Analytic 1080","description":"Monitors for the creation of accounts inside containers using names that resemble legitimate orchestrator or backup identities to mask adversary persistence.","url":"https://attack.mitre.org/detectionstrategies/DET0383#AN1080","platforms":["Containers"],"log_source_references":[{"name":"docker:daemon","channel":"ExecCreate + usermod or useradd","data_component":"DC0014","data_component_name":"User Account Creation","log_source_slug":"docker-daemon"}],"mutable_elements":[{"field":"ContainerContextScope","description":"Limit detection to containers with persistent volumes or specific workloads"},{"field":"MasqueradePatternList","description":"Custom list of commonly abused names to blend into container environments (e.g., kubelet, cronjob_sync)"}],"live":true,"detection_strategies":["DET0383"],"techniques":["T1036.010"]}],"live":true,"version":"1.0","techniques":["T1036.010"]}],"sigma_rules":[],"kev_cves":[],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}