Analytics Alerts
Browse the Cortex analytics alert reference.
1 alert match the current filters. tactic: TA0003 ✕ technique: T1098 ✕
Download CSV Show ATT&CK heatmapA user enabled a default local account Informational Identity Analytics 2 variations
A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003)ATT&CK techniques: Valid Accounts: Default Accounts (T1078.001) Account Manipulation (T1098)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: An attacker may attempt to gain access to the account and escalate privileges.Investigative actions: Check what rights and permissions were granted to the user. Verify this action with the user who performed the change. Follow actions and activities of the newly enabled default account.Variations
A user enabled the Windows DefaultAccount
Low overridden
A user enabled the Windows DefaultAccount. Enabling a default account may pose a security risk, as they are often exploited by attackers. overridden
A user enabled the Windows default Guest account
Low overridden
A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers. overridden