kevmap

Techniques › T1136

T1136 Create Account

persistence — Windows, IaaS, Linux, macOS, Network Devices, Containers, SaaS, Office Suite, Identity Provider, ESXi · attack.mitre.org · JSON

1
MITRE detection strategy
5
analytics
3
Sigma rules tagged attack.t1136
10
KEV CVEs mapped here
<p>Adversaries may create an account to maintain access to victim systems. With a sufficient level of access, creating such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.</p><p>Accounts may be created on the local system or within a domain or cloud tenant. In cloud environments, adversaries may create accounts that only have access to specific services, which can reduce the chance of detection.</p>

KEV CVEs mapped to this technique · CTID Mappings Explorer

CVEVendor / productMapping typeStateAdded
CVE-2025-31161CrushFTP CrushFTP primary impact Mapped2025-04-07
CVE-2023-20198Cisco IOS XE Web UI primary impact Mapped2023-10-16
CVE-2023-22515Atlassian Confluence Data Center and Server primary impact Mapped2023-10-05
CVE-2023-35078Ivanti Endpoint Manager Mobile (EPMM) primary impact Mapped2023-07-25
CVE-2023-27997Fortinet FortiOS and FortiProxy SSL-VPN primary impact Mapped2023-06-13
CVE-2023-34362Progress MOVEit Transfer secondary impact Mapped2023-06-02
CVE-2023-28252Microsoft Windows secondary impact Mapped2023-04-11
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus (SDP) / SupportCenter Plus secondary impact Mapped2021-12-01
CVE-2021-34473Microsoft Exchange Server secondary impact Mapped2021-11-03
CVE-2021-40539Zoho ManageEngine secondary impact Mapped2021-11-03

Detection strategy · ATT&CK Enterprise v19.2

Sigma rules · SigmaHQ da9bb07d64, tag attack.t1136

Author: Austin Songer @austinsonger · 2021-07-24 (modified 2022-10-09) · logsource: product=aws service=cloudtrail · 4ae68615-866f-4304-b24b-ba048dfa5ca7
Detects when an ElastiCache security group has been created.
Techniques: T1136T1136.003
Author: Cedric Maurugeon · 2023-08-22 · logsource: product=linux category=process_creation · b28e4eb3-8bbc-4f0c-819f-edfe8e2f25db
Detects user account creation on ESXi system via esxcli
Techniques: T1136T1059.012
Author: Leo Tsaousis (@laripping) · 2024-03-26 · logsource: product=kubernetes category=application service=audit · e31bae15-83ed-473e-bf31-faf4f8a17d36
Detects creation of new Kubernetes service account, which could indicate an attacker's attempt to persist within a cluster.
Techniques: T1136

Sub-techniques

IDNameSigma rulesKEV CVEs
T1136.001Local Account182
T1136.002Domain Account60
T1136.003Cloud Account30