Analytics BIOC Informational

A user enabled a default local account

A user enabled a default local account. Enabling a default account may pose a security risk, as they are often exploited by attackers.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Initial Access (TA0001) Persistence (TA0003)
ATT&CK techniques: Valid Accounts: Default Accounts (T1078.001) Account Manipulation (T1098)
Attacker's goals:

An attacker may attempt to gain access to the account and escalate privileges.

Investigative actions:

Check what rights and permissions were granted to the user. Verify this action with the user who performed the change. Follow actions and activities of the newly enabled default account.

Test period:
N/A (single event)
Deduplication:
1 Day
2 variations:
  • A user enabled the Windows DefaultAccount Low (parent: Informational)
  • A user enabled the Windows default Guest account Low (parent: Informational)