A user enabled a default local account
Synopsis
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
Requires one of the following data sources: Windows Event Collector OR XDR Agent with eXtended Threat Hunting (XTH)
Detection Modules
Identity Analytics
ATT&CK Tactic
Initial Access (TA0001), Persistence (TA0003)
ATT&CK Technique
Valid Accounts: Default Accounts (T1078.001), Account Manipulation (T1098)
Severity
Informational
Description
A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers.
Attacker's Goals
An attacker may attempt to gain access to the account and escalate privileges.
Investigative actions
Check what rights and permissions were granted to the user.
Verify this action with the user who performed the change.
Follow actions and activities of the newly enabled default account.
Variations
Was this helpful?
