Skip to content
Every technique
T1078.003No distinct observable

Local Accounts

Stealth · Persistence · Privilege Escalation · Initial AccessContainers, ESXi, Linux, macOS, Network Devices, Windows

Where this stands

A reviewer read the telemetry and concluded there is nothing here to detect that a sibling technique does not already cover.

All three analytics in DET0407 are framed as baseline/anomaly comparisons, the same shape T1078 and T1078.002 were already declined for. AN1137 (Windows, 4624/4648/4672) asks to detect 'anomalous usage... especially accounts not typically used interactively or outside business hours' and its own mutableElements ask for a TimeWindow ('tune for normal business hours') and a UserContext list of 'legitimate local users' — a per-account allowlist and a time-of-day comparison, neither of which is a field on the event; lib/sigma has no aggregation, timeframe or per-account history to build either from. AN1138 (Linux, auditd USER_LOGIN / linux:auth sshd) asks for logins 'outside expected operational context or at anomalous times' with a HostRole knob ('server vs. workstation') that is organisational metadata, not anything USER_LOGIN or sshd emits. […]

Covered instead by T1078, T1078.002.

What the technique is

Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.

Read it on attack.mitre.org

What MITRE says you would watch

  • AN1137

    Detects anomalous usage of local accounts to log into a system, especially accounts not typically used interactively or outside business hours.

  • AN1138

    Detects interactive or service logins from local accounts outside expected operational context or at anomalous times.

  • AN1139

    Detects abnormal or rare logins via local accounts through system or remote mechanisms such as SSH.

Technique names and descriptions © MITRE ATT&CK®, CC BY 4.0. Not endorsed by MITRE.