Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Data Components DC0014 — User Account Creation
DC0014

User Account Creation

17 analytic(s) · 6 detection strategy(ies)

Description

The initial establishment of a new user, service, or machine account within an operating system, cloud environment, or identity management system.

Referenced in Analytics

17
AN0006 Analytic 0006 DET0003

Adversary uses built-in tools such as 'net user /add /domain' or PowerShell to create a domain user account. The behavior chain includes: (1) suspicious process execution on a domain controller followed by (2) user account creation event (Event ID 4720) on the same host.

WinEventLog:Security WinEventLog:Sysmon
AN0899 Analytic 0899 DET0319

Adversaries create user accounts via identity provider APIs or admin portals (e.g., Azure AD, Okta). These accounts may be assigned elevated privileges or used in chained authentication. Detection monitors Add User activity from suspicious IPs or automation sources, followed by role/permission escalation.

azure:audit azure:audit azure:signinlogs
AN0900 Analytic 0900 DET0319

Adversaries use cloud API, CLI, or console to create IAM users or roles. Initial CreateUser is followed by policy/role attachment. Detection monitors temporal chains involving IAM:CreateUser, AttachUserPolicy, and credential generation, especially from automation or foreign IP ranges.

AWS:CloudTrail AWS:CloudTrail
AN0901 Analytic 0901 DET0319

Adversaries create SaaS accounts via admin dashboards or integrations (e.g., Zoom, Salesforce, Slack). Monitor lifecycle.create or account provisioning events from non-standard sources or times.

saas:zoom
AN0902 Analytic 0902 DET0319

Adversaries leverage M365 or Google Workspace APIs to create users, service accounts, or guest accounts. Follow-on behaviors include login activity, role escalation, or service principal token generation.

m365:unified m365:unified
AN1001 Analytic 1001 DET0353

Registry modifications to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList setting user visibility to 0, or creation of user accounts not shown on login screen. Defender view: correlation of account creation with registry edits that mark users hidden.

WinEventLog:Security WinEventLog:Sysmon
AN1077 Analytic 1077 DET0383

Detects adversary behavior where a newly created or renamed user account closely resembles existing service or administrator accounts to blend in and avoid detection. Common patterns include prefix/suffix modifications, homoglyphs, or use of names like 'admin1', 'adm1n', or 'backup_help'.

WinEventLog:Security windows:osquery
AN1078 Analytic 1078 DET0383

Detects creation or renaming of accounts with names that closely match known service, root, or admin accounts. Behavior often follows account discovery or deletion, attempting to blend into system activity logs using trusted name conventions.

auditd:SYSCALL auditd:SYSCALL linux:osquery
AN1079 Analytic 1079 DET0383

Detects adversary creation of cloud or IdP accounts whose names resemble existing privileged or service accounts. May indicate preparation for privilege escalation or defense evasion.

azure:audit azure:audit saas:okta
AN1080 Analytic 1080 DET0383

Monitors for the creation of accounts inside containers using names that resemble legitimate orchestrator or backup identities to mask adversary persistence.

docker:daemon
AN1235 Analytic 1235 DET0447

Adversary uses built-in tools like 'net user /add', PowerShell, or WMI to create a local user. Sequence: Account creation event (4720) follows process creation of a suspicious executable (e.g., powershell.exe or net.exe).

WinEventLog:Security WinEventLog:Sysmon
AN1236 Analytic 1236 DET0447

Local user accounts are created via binaries like 'useradd', 'adduser', or by editing passwd/shadow. Behavior chain includes execution of user management binaries or modification of user database files.

auditd:SYSCALL auditd:SYSCALL
AN1240 Analytic 1240 DET0447

Account created via CLI using 'username' command or REST API. Detectable through AAA logging or CLI history telemetry.

networkdevice:syslog
AN1604 Analytic 1604 DET0583

Adversary uses built-in OS tools or API calls to create local or domain accounts for persistence or lateral movement. Tools such as 'net user', PowerShell, or MMC snap-ins may be used. Detection focuses on Event ID 4720 paired with process lineage and user context.

WinEventLog:Security WinEventLog:Sysmon
AN1605 Analytic 1605 DET0583

Adversary invokes 'useradd', 'adduser', or equivalent system commands or scripts to create local users. Detection focuses on command execution and audit trail of passwd/shadow file modifications.

auditd:SYSCALL auditd:SYSCALL
AN1607 Analytic 1607 DET0583

Adversary creates users via IAM/IdP API or portal (e.g., Azure AD, Okta). Detection involves monitoring API calls, admin action logs, and correlation with role assignments.

azure:audit
AN1608 Analytic 1608 DET0583

Account creation via cloud service APIs or CLI, often associated with key generation. Monitored via CloudTrail or equivalent audit logs.

AWS:CloudTrail AWS:CloudTrail

Details

MITRE ID
DC0014
STIX ID
x-mitre-data-component--deb22295-7e37-4a3b-ac6f-c86666fbe63d
Analytics
17
Detection Strategies
6
Leaving Threaticon

This link opens an external site that isn't part of the platform.