Analytics BIOC
Informational
✕
A user enabled a default local account
A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003)
ATT&CK techniques: Valid Accounts: Default Accounts (T1078.001) Account Manipulation (T1098)
Attacker's goals:
An attacker may attempt to gain access to the account and escalate privileges.
Investigative actions:
Check what rights and permissions were granted to the user. Verify this action with the user who performed the change. Follow actions and activities of the newly enabled default account.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day
2 variations:
- A user enabled the Windows DefaultAccount Low (parent: Informational)
- A user enabled the Windows default Guest account Low (parent: Informational)