Analytics Alerts
Browse the Cortex analytics alert reference.
3 alerts match the current filters. technique: T1078 ✕
Download CSV Show ATT&CK heatmapLinux local user account creation Informational Identity Analytics 1 variation
A user executed a process associated with user account creation.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Valid Accounts (T1078) Valid Accounts: Local Accounts (T1078.003)Required data: XDR AgentAttacker's goals: Persistence using a valid account.Investigative actions: Check the user who created the account and verify its activity. Investigate whether the same account was created on different hosts as part of an installation process.Variations
Linux local user account creation by non-root user
Low overridden
A non-root user executed a process associated with user account creation. This user does not regularly create accounts. overridden
Local user account creation Informational Identity Analytics 1 variation
A user was observed creating a rare local user account.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Valid Accounts: Local Accounts (T1078.003)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Persistence using a valid account.Investigative actions: Check the user who created the account and verify its activity. Investigate whether the same account was created on different hosts as part of an installation process.Variations
Suspicious local user account creation
Low overridden
A user was observed creating a rare local user account. This user has not been seen creating user accounts in the past 30 days. overridden
Local user account creation by a machine account Informational Identity Analytics
A machine account was observed creating a rare local user account.
- Activation:
- 14 Days
- Training:
- 30 Days
- Test:
- N/A (single event)
- Deduplication:
- 1 Day
ATT&CK tactics: Persistence (TA0003)ATT&CK techniques: Valid Accounts: Local Accounts (T1078.003)Required data: Windows Event Collector XDR Agent with eXtended Threat Hunting (XTH)Attacker's goals: Persistence using a valid account.Investigative actions: Check the machine that created the user account and verify its activity. Check if the machine account is supposed to create user accounts. Investigate whether the same account was created on different hosts as part of an installation process.