Skip to content
Every technique
T1078.002No distinct observable

Domain Accounts

Stealth · Persistence · Privilege Escalation · Initial AccessESXi, Linux, macOS, Windows

Where this stands

A reviewer read the telemetry and concluded there is nothing here to detect that a sibling technique does not already cover.

Every analytic in DET0210 describes a baseline comparison, not an event. AN0590 asks for 'logon behavior across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations' over Security 4624/4625/4768/4769; AN0591 asks for sssd/winbind logons 'outside of typical patterns'; AN0592 asks for Open Directory logins 'outside business hours or on atypical endpoints'. All three need counting, time-of-day windows, or per-account history, and lib/sigma models none of those — no aggregations, no timeframes, no near. Stripped of the baseline, the residue is 'a domain account authenticated', which every 4624 in a domain satisfies: the rule would fire on every successful logon in the estate, which is the silent failure this corpus exists to avoid. […]

Covered instead by T1078, T1110, T1558.003, T1550.002.

What the technique is

Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover users, administrators, and services. Adversaries may compromise domain accounts, some with a high level of privileges, through various means such as OS Credential Dumping or password reuse, allowing access to privileged resources of the domain.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN0590

    Detection of suspicious logon behavior using valid domain accounts across multiple hosts, off-hours, or simultaneous sessions from geographically distant locations.

  • AN0591

    Use of domain accounts via sssd or winbind for logon activity outside of typical patterns, especially on sensitive systems or with lateral movement tools.

  • AN0592

    Domain logins using network accounts or mobile accounts via Open Directory or Active Directory plugins, especially outside business hours or on atypical endpoints.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.