T1136.001: Local Account
Summary
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. For example, with a sufficient level of access, the Windows <code>net user /add</code> command can be used to create a local account. In Linux, the `useradd` command can be used, while on macOS systems, the <code>dscl -create</code> command can be used. Local accounts may also be added to network devices, often via common [Network Device CLI](https://attack.mitre.org/techniques/T1059/008) commands such as <code>username</code>, to ESXi servers via `esxcli system account add`, or to Kubernetes clusters using the `kubectl` utility.(Citation: cisco_username_cmd)(Citation: Kubernetes Service Accounts Security) Adversaries may also create new local accounts on network firewall management consoles – for example, by exploiting a vulnerable firewall management system, threat actors may be able to establish super-admin accounts that could be used to modify firewall rules and gain further access to the network.(Citation: Cyber Security News) Such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.
Source Attribution
Source: MITRE ATT&CK · Confidence: high
Platforms
- Containers
- ESXi
- Linux
- macOS
- Network Devices
- Windows
Tactic
persistence
References
- https://attack.mitre.org/techniques/T1136/001
- https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/security/s1/sec-s1-cr-book/sec-cr-t2.html#wp1047035630
- https://cybersecuritynews.com/superblack-actors-exploiting-two-fortinet-vulnerabilities/
- https://kubernetes.io/docs/concepts/security/service-accounts/
- https://docs.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4720