A newer version is available. For the latest information, see the
current release documentation.
User Account Creationedit
Identifies attempts to create new local users. This is sometimes done by attackers to increase access to a system or domain.
Rule indices:
- winlogbeat-*
Severity: low
Risk score: 21
Runs every: 5 minutes
Searches indices from: now-6m (Date Math format, see also Additional look-back time
)
Maximum signals per execution: 100
Tags:
- Elastic
- Windows
Rule version: 1
Added (Elastic Stack release): 7.6.0
Rule queryedit
event.action:"Process Create (rule: ProcessCreate)" and process.name:("net.exe" or "net1.exe") and not process.parent.name:"net.exe" and process.args:("user" and ("/add" or "/ad"))
Threat mappingedit
Framework: MITRE ATT&CKTM
-
Tactic:
- Name: Persistence
- ID: TA0003
- Reference URL: https://attack.mitre.org/tactics/TA0003/
-
Technique:
- Name: Create Account
- ID: T1136
- Reference URL: https://attack.mitre.org/techniques/T1136/