{"id":"T1136.001","name":"Local Account","url":"https://attack.mitre.org/techniques/T1136/001","tactics":["persistence"],"platforms":["Containers","ESXi","Linux","macOS","Network Devices","Windows"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0447","stix_id":"x-mitre-detection-strategy--2250ba04-1b95-4c72-9373-d87e8c1d7869","name":"T1136.001 Detection Strategy - Local Account Creation Across Platforms","url":"https://attack.mitre.org/detectionstrategies/DET0447","analytics":[{"id":"AN1235","stix_id":"x-mitre-analytic--4e4c318b-5da0-46f7-aed2-d37828e4831b","name":"Analytic 1235","description":"Adversary uses built-in tools like 'net user /add', PowerShell, or WMI to create a local user. Sequence: Account creation event (4720) follows process creation of a suspicious executable (e.g., powershell.exe or net.exe).","url":"https://attack.mitre.org/detectionstrategies/DET0447#AN1235","platforms":["Windows"],"log_source_references":[{"name":"WinEventLog:Security","channel":"EventCode=4720","data_component":"DC0014","data_component_name":"User Account Creation","log_source_slug":"wineventlog-security"},{"name":"WinEventLog:Sysmon","channel":"EventCode=1","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"wineventlog-sysmon"}],"mutable_elements":[{"field":"ParentProcessName","description":"Attackers may use cmd.exe, wscript.exe, or renamed binaries to evade detection"},{"field":"TimeWindow","description":"Define time threshold between process start and user creation event (e.g., 5s–2m)"},{"field":"UserContext","description":"Correlate if process runs under SYSTEM, Administrator, or untrusted account"}],"live":true,"detection_strategies":["DET0447"],"techniques":["T1136.001"]},{"id":"AN1236","stix_id":"x-mitre-analytic--ee065e5f-5a04-49bd-b2b6-33b404ac37c7","name":"Analytic 1236","description":"Local user accounts are created via binaries like 'useradd', 'adduser', or by editing passwd/shadow. Behavior chain includes execution of user management binaries or modification of user database files.","url":"https://attack.mitre.org/detectionstrategies/DET0447#AN1236","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"useradd or adduser executed","data_component":"DC0014","data_component_name":"User Account Creation","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"write operation on /etc/passwd or /etc/shadow","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"BinaryPath","description":"Account creation may be scripted via shell scripts, cron jobs, or remote shells"},{"field":"ExecutionSource","description":"Flag if commands are issued from remote sessions (e.g., sshd)"}],"live":true,"detection_strategies":["DET0447"],"techniques":["T1136.001"]},{"id":"AN1237","stix_id":"x-mitre-analytic--45e8fdaf-60cc-46db-a9fd-5dc18c8db6bb","name":"Analytic 1237","description":"Account creation using 'dscl -create' or via GUI tools. Detection involves command execution and file changes to the local directory services database.","url":"https://attack.mitre.org/detectionstrategies/DET0447#AN1237","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"dscl -create","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"modification to /var/db/dslocal/nodes/Default/users/","data_component":"DC0061","data_component_name":"File Modification","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"UsernamePattern","description":"Accounts like 'svc*', 'backup*' may blend into legit naming patterns"},{"field":"SessionOrigin","description":"Identify if dscl was run locally, via ARD, or Terminal.app"}],"live":true,"detection_strategies":["DET0447"],"techniques":["T1136.001"]},{"id":"AN1238","stix_id":"x-mitre-analytic--b7a63a7c-e8c2-4a25-becf-299ea45996e5","name":"Analytic 1238","description":"Account created using esxcli commands. Sequence includes esxcli execution and successful modification to account DB.","url":"https://attack.mitre.org/detectionstrategies/DET0447#AN1238","platforms":["ESXi"],"log_source_references":[{"name":"esxi:vmkernel","channel":"esxcli system account add","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"esxi-vmkernel"}],"mutable_elements":[{"field":"CommandOrigin","description":"Console sessions vs SSH vs vSphere CLI session may affect alert fidelity"}],"live":true,"detection_strategies":["DET0447"],"techniques":["T1136.001"]},{"id":"AN1239","stix_id":"x-mitre-analytic--ac204e03-5c8c-4e29-929c-780145a98669","name":"Analytic 1239","description":"Account created in a running container (e.g., via 'useradd' or by modifying /etc/passwd directly). Detectable via runtime telemetry (e.g., Falco or eBPF hooks).","url":"https://attack.mitre.org/detectionstrategies/DET0447#AN1239","platforms":["Containers"],"log_source_references":[{"name":"ebpf:syscalls","channel":"useradd or /etc/passwd modified inside container","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"ebpf-syscalls"}],"mutable_elements":[{"field":"ContainerContext","description":"Distinguish between ephemeral containers and long-lived service containers"},{"field":"NamespaceScope","description":"Determine if account was added inside host, user, or PID namespace"}],"live":true,"detection_strategies":["DET0447"],"techniques":["T1136.001"]},{"id":"AN1240","stix_id":"x-mitre-analytic--614594ba-9590-4fa9-871c-3e092882c74c","name":"Analytic 1240","description":"Account created via CLI using 'username' command or REST API. Detectable through AAA logging or CLI history telemetry.","url":"https://attack.mitre.org/detectionstrategies/DET0447#AN1240","platforms":["Network Devices"],"log_source_references":[{"name":"networkdevice:syslog","channel":"username <user> privilege <level>","data_component":"DC0014","data_component_name":"User Account Creation","log_source_slug":"networkdevice-syslog"}],"mutable_elements":[{"field":"PrivilegeLevel","description":"Some devices allow unprivileged user creation—adjust based on role risk"},{"field":"RemoteSessionFlag","description":"Creation via Telnet, SSH, or serial console affects detection priority"}],"live":true,"detection_strategies":["DET0447"],"techniques":["T1136.001"]}],"live":true,"version":"1.0","techniques":["T1136.001"]}],"sigma_rules":[{"id":"0ac15ec3-d24f-4246-aa2a-3077bb1cf90e","title":"Privileged User Has Been Created","author":"Pawel Mazur","status":"test","level":"high","date":"2022-12-21","modified":"2025-01-21","description":"Detects the addition of a new user to a privileged group such as \"root\" or \"sudo\"","references":["https://digital.nhs.uk/cyber-alerts/2018/cc-2825","https://linux.die.net/man/8/useradd","https://github.com/redcanaryco/atomic-red-team/blob/25acadc0b43a07125a8a5b599b28bbc1a91ffb06/atomics/T1136.001/T1136.001.md#atomic-test-5---create-a-new-user-in-linux-with-root-uid-and-gid"],"logsource":{"product":"linux"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1136.001","attack.t1098"],"path":"rules/linux/builtin/lnx_privileged_user_creation.yml","techniques":["T1136.001","T1098"],"cves":[]},{"id":"1bbf25b9-8038-4154-a50b-118f2a32be27","title":"Suspicious Windows ANONYMOUS LOGON Local Account Created","author":"James Pemberton / @4A616D6573","status":"test","level":"high","date":"2019-10-31","modified":"2022-10-09","description":"Detects the creation of suspicious accounts similar to ANONYMOUS LOGON, such as using additional spaces. Created as an covering detection for exclusion of Logon Type 3 from ANONYMOUS LOGON accounts.","references":["https://twitter.com/SBousseaden/status/1189469425482829824"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.t1136.001","attack.t1136.002"],"path":"rules/windows/builtin/security/win_security_susp_local_anon_logon_created.yml","techniques":["T1136.001","T1136.002"],"cves":[]},{"id":"243de76f-4725-4f2e-8225-a8a69b15ad61","title":"PowerShell Create Local User","author":"@ROxPinTeddy","status":"test","level":"medium","date":"2020-04-11","modified":"2022-12-25","description":"Detects creation of a local user via PowerShell","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1136.001/T1136.001.md"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.execution","attack.t1059.001","attack.persistence","attack.t1136.001"],"path":"rules/windows/powershell/powershell_script/posh_ps_create_local_user.yml","techniques":["T1059.001","T1136.001"],"cves":[]},{"id":"460479f3-80b7-42da-9c43-2cc1d54dbccd","title":"Creation of a Local Hidden User Account by Registry","author":"Christian Burkard (Nextron Systems)","status":"test","level":"high","date":"2021-05-03","modified":"2025-10-31","description":"Sysmon registry detection of a local hidden user account.","references":["https://twitter.com/SBousseaden/status/1387530414185664538"],"logsource":{"product":"windows","category":"registry_event"},"tags":["attack.persistence","attack.t1136.001"],"path":"rules/windows/registry/registry_event/registry_event_add_local_hidden_user.yml","techniques":["T1136.001"],"cves":[]},{"id":"51719bf5-e4fd-4e44-8ba8-b830e7ac0731","title":"Creation Of A Local User Account","author":"Alejandro Ortuno, oscd.community","status":"test","level":"low","date":"2020-10-06","modified":"2023-02-18","description":"Detects the creation of a new user account. Such accounts may be used for persistence that do not require persistent remote access tools to be deployed on the system.","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1136.001/T1136.001.md","https://ss64.com/osx/sysadminctl.html"],"logsource":{"product":"macos","category":"process_creation"},"tags":["attack.t1136.001","attack.persistence"],"path":"rules/macos/process_creation/proc_creation_macos_create_account.yml","techniques":["T1136.001"],"cves":[]},{"id":"66b6be3d-55d0-4f47-9855-d69df21740ea","title":"Local User Creation","author":"Patrick Bareiss","status":"test","level":"low","date":"2019-04-18","modified":"2021-01-17","description":"Detects local user creation on Windows servers, which shouldn't happen in an Active Directory environment. Apply this Sigma Use Case on your Windows server logs and not on your DC logs.\n","references":["https://patrick-bareiss.com/detecting-local-user-creation-in-ad-with-sigma/"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.t1136.001"],"path":"rules/windows/builtin/security/win_security_user_creation.yml","techniques":["T1136.001"],"cves":[]},{"id":"6d844f0f-1c18-41af-8f19-33e7654edfc3","title":"Cisco Local Accounts","author":"Austin Clark","status":"test","level":"high","date":"2019-08-12","modified":"2023-01-04","description":"Find local accounts being created or modified as well as remote authentication configurations","references":[],"logsource":{"product":"cisco","service":"aaa"},"tags":["attack.privilege-escalation","attack.persistence","attack.t1136.001","attack.t1098"],"path":"rules/network/cisco/aaa/cisco_cli_local_accounts.yml","techniques":["T1136.001","T1098"],"cves":[]},{"id":"75578840-9526-4b2a-9462-af469a45e767","title":"Serv-U Exploitation CVE-2021-35211 by DEV-0322","author":"Florian Roth (Nextron Systems)","status":"test","level":"critical","date":"2021-07-14","modified":"2022-12-18","description":"Detects patterns as noticed in exploitation of Serv-U CVE-2021-35211 vulnerability by threat group DEV-0322","references":["https://www.microsoft.com/security/blog/2021/07/13/microsoft-discovers-threat-actor-targeting-solarwinds-serv-u-software-with-0-day-exploit/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.t1136.001","cve.2021-35211","detection.emerging-threats"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-35211/proc_creation_win_exploit_cve_2021_35211_servu.yml","techniques":["T1136.001"],"cves":["CVE-2021-35211"]},{"id":"759d0d51-bc99-4b5e-9add-8f5b2c8e7512","title":"Creation Of An User Account","author":"Marie Euler, Pawel Mazur","status":"test","level":"medium","date":"2020-05-18","modified":"2022-12-20","description":"Detects the creation of a new user account. Such accounts may be used for persistence that do not require persistent remote access tools to be deployed on the system.","references":["https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/7/html/security_guide/sec-understanding_audit_log_files","https://access.redhat.com/articles/4409591#audit-record-types-2","https://www.youtube.com/watch?v=VmvY5SQm5-Y&ab_channel=M45C07"],"logsource":{"product":"linux","service":"auditd"},"tags":["attack.t1136.001","attack.persistence"],"path":"rules/linux/auditd/syscall/lnx_auditd_create_account.yml","techniques":["T1136.001"],"cves":[]},{"id":"7b449a5e-1db5-4dd0-a2dc-4e3a67282538","title":"Hidden Local User Creation","author":"Christian Burkard (Nextron Systems)","status":"test","level":"high","date":"2021-05-03","modified":"2024-01-16","description":"Detects the creation of a local hidden user account which should not happen for event ID 4720.","references":["https://twitter.com/SBousseaden/status/1387743867663958021"],"logsource":{"product":"windows","service":"security"},"tags":["attack.persistence","attack.t1136.001"],"path":"rules/windows/builtin/security/win_security_hidden_user_creation.yml","techniques":["T1136.001"],"cves":[]},{"id":"7c9fed65-039a-4055-8c23-fa763d94aff6","title":"New User Account Creation Attempt Via ADSI in CommandLine","author":"William Gokah (idea), Raylee Hawkins, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2026-08-13","modified":null,"description":"Detects PowerShell command line arguments containing ADSI (Active Directory Service Interfaces) patterns\ntrying to create a new user account via the WinNT or LDAP provider. This is an uncommon method to create\nuser accounts and may indicate an attempt to evade detection by avoiding more commonly monitored commands\nsuch as \"net user\", \"New-LocalUser\" or \"New-ADUser\".\n","references":["https://learn.microsoft.com/en-us/windows/win32/adsi/user-creation-with-the-adsi-ldap-provider","https://learn.microsoft.com/en-us/windows/win32/adsi/adsi-winnt-provider"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.t1136.001","attack.t1136.002"],"path":"rules/windows/process_creation/proc_creation_win_powershell_adsi_create_user.yml","techniques":["T1136.001","T1136.002"],"cves":[]},{"id":"b9f0e6f5-09b4-4358-bae4-08408705bd5c","title":"New User Created Via Net.EXE With Never Expire Option","author":"Nasreddine Bencherchali (Nextron Systems)","status":"test","level":"high","date":"2022-07-12","modified":"2023-02-21","description":"Detects creation of local users via the net.exe command with the option \"never expire\"","references":["https://thedfirreport.com/2022/07/11/select-xmrig-from-sqlserver/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.t1136.001"],"path":"rules/windows/process_creation/proc_creation_win_net_user_add_never_expire.yml","techniques":["T1136.001"],"cves":[]},{"id":"bf906d7b-7070-4642-8383-e404cf26eba5","title":"DarkGate - User Created Via Net.EXE","author":"X__Junior (Nextron Systems)","status":"test","level":"high","date":"2023-08-27","modified":"2023-10-15","description":"Detects creation of local users via the net.exe command with the name of \"DarkGate\"","references":["Internal Research"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.t1136.001","detection.emerging-threats"],"path":"rules-emerging-threats/2023/Malware/DarkGate/proc_creation_win_malware_darkgate_net_user_creation.yml","techniques":["T1136.001"],"cves":[]},{"id":"cd0a4943-0edd-42cf-b50c-06f77a10d4c1","title":"FortiGate - New Administrator Account Created","author":"Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"medium","date":"2025-11-01","modified":null,"description":"Detects the creation of an administrator account on a Fortinet FortiGate Firewall.","references":["https://www.fortiguard.com/psirt/FG-IR-24-535","https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/398/event","https://docs.fortinet.com/document/fortigate/7.6.4/cli-reference/390485493/config-system-admin","https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/44547/44547-logid-event-config-objattr"],"logsource":{"product":"fortigate","service":"event"},"tags":["attack.persistence","attack.t1136.001"],"path":"rules/network/fortinet/fortigate/fortinet_fortigate_new_admin_account_created.yml","techniques":["T1136.001"],"cves":[]},{"id":"cd219ff3-fa99-45d4-8380-a7d15116c6dc","title":"New User Created Via Net.EXE","author":"Endgame, JHasenbusch (adapted to Sigma for oscd.community)","status":"test","level":"medium","date":"2018-10-30","modified":"2023-02-21","description":"Identifies the creation of local users via the net.exe command.","references":["https://eqllib.readthedocs.io/en/latest/analytics/014c3f51-89c6-40f1-ac9c-5688f26090ab.html","https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1136.001/T1136.001.md"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.persistence","attack.t1136.001"],"path":"rules/windows/process_creation/proc_creation_win_net_user_add.yml","techniques":["T1136.001"],"cves":[]},{"id":"ddbbe845-1d74-43a8-8231-2156d180234d","title":"FortiGate - New Local User Created","author":"Marco Pedrinazzi (@pedrinazziM) (InTheCyber)","status":"experimental","level":"medium","date":"2025-11-01","modified":null,"description":"Detects the creation of a new local user on a Fortinet FortiGate Firewall.\nThe new local user could be used for VPN connections.\n","references":["https://www.fortiguard.com/psirt/FG-IR-24-535","https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/398/event","https://docs.fortinet.com/document/fortigate/7.6.4/cli-reference/109120963/config-user-local","https://docs.fortinet.com/document/fortigate/7.6.4/fortios-log-message-reference/44547/44547-logid-event-config-objattr"],"logsource":{"product":"fortigate","service":"event"},"tags":["attack.persistence","attack.t1136.001"],"path":"rules/network/fortinet/fortigate/fortinet_fortigate_new_local_user_created.yml","techniques":["T1136.001"],"cves":[]},{"id":"e50d5d26-0cf6-4045-b82b-13c0a4e316be","title":"New User Account Creation Attempt Via ADSI","author":"William Gokah (idea), Raylee Hawkins, Swachchhanda Shrawan Poudel (Nextron Systems)","status":"experimental","level":"medium","date":"2026-08-13","modified":null,"description":"Detects an attempt to create a new user account via ADSI (Active Directory Service Interfaces)\nusing either the WinNT or LDAP provider. This is an uncommon method to create user accounts\nand may indicate an attempt to evade detection by avoiding more commonly monitored commands\nsuch as \"net user\", \"New-LocalUser\" or \"New-ADUser\".\n","references":["https://learn.microsoft.com/en-us/windows/win32/adsi/user-creation-with-the-adsi-ldap-provider","https://learn.microsoft.com/en-us/windows/win32/adsi/adsi-winnt-provider"],"logsource":{"product":"windows","category":"ps_script"},"tags":["attack.persistence","attack.t1136.001","attack.t1136.002"],"path":"rules/windows/powershell/powershell_script/posh_ps_adsi_create_user.yml","techniques":["T1136.001","T1136.002"],"cves":[]},{"id":"ffa28e60-bdb1-46e0-9f82-05f7a61cc06e","title":"User Added to Remote Desktop Users Group","author":"Florian Roth (Nextron Systems)","status":"test","level":"high","date":"2021-12-06","modified":"2022-09-09","description":"Detects addition of users to the local Remote Desktop Users group via \"Net\" or \"Add-LocalGroupMember\".","references":["https://www.microsoft.com/security/blog/2021/11/16/evolving-trends-in-iranian-threat-actor-activity-mstic-presentation-at-cyberwarcon-2021/"],"logsource":{"product":"windows","category":"process_creation"},"tags":["attack.initial-access","attack.persistence","attack.lateral-movement","attack.t1133","attack.t1136.001","attack.t1021.001"],"path":"rules/windows/process_creation/proc_creation_win_susp_add_user_remote_desktop_group.yml","techniques":["T1133","T1136.001","T1021.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2022-47966","state":"mapped","mapping_types":["primary_impact"]},{"cveID":"CVE-2022-21999","state":"mapped","mapping_types":["secondary_impact"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}