Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Detection Strategies DET0407 — Detection of Local Account Abuse for Initial Access and Persistence
DET0407

Detection of Local Account Abuse for Initial Access and Persistence

3 analytic(s) · 1 technique(s) detected

Analytics

3
AN1137 Analytic 1137
Windows

Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours.

WinEventLog:Security EventCode=4624, 4648 WinEventLog:Security EventCode=4672
[TimeWindow] Tune for normal business hours to reduce false positives from legitimate after-hours work.
[UserContext] Define list of legitimate local users for interactive access.
AN1138 Analytic 1138
Linux

Detects interactive or service logins from local accounts outside expected operational context or at anomalous times.

auditd:USER_LOGIN USER_LOGIN linux:auth sshd login
[TimeWindow] Define operational hours or expected login times per host.
[HostRole] Differentiate expected behavior for server vs. workstation.
AN1139 Analytic 1139
macOS

Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH.

macos:unifiedlog loginwindow or sshd
[UserContext] Restrict expected local users by device owner or role.
[TimeWindow] Set appropriate bounds based on endpoint usage patterns.

Detected Techniques

1

Details

MITRE ID
DET0407
STIX ID
x-mitre-detection-strategy--b045b89e-3095-41c3-a04d-d40075f14cd8
Analytics
3
Techniques Detected
1
By Tactic
Stealth
1
Leaving Threaticon

This link opens an external site that isn't part of the platform.