Analytics BIOC Low

Masquerading as a default local account

A user created a new local account with the name of a default local account, such as Guest and DefaultAccount. An attacker may create a user with these known names to evade detection.

Module:
Identity Analytics
Data source:
Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Defense Evasion (TA0005) Persistence (TA0003)
ATT&CK techniques: Hide Artifacts: Hidden Users (T1564.002) Valid Accounts: Default Accounts (T1078.001) Masquerading (T1036)
Attacker's goals:

An attacker is attempting to evade detection.

Investigative actions:

Check what rights and permissions were granted to the new user. Verify the action with the user who created the new account. Follow actions and activities of the newly created default account. Monitor the addition of the user to different groups.

Test period:
N/A (single event)
Deduplication:
1 Day
3 variations:
  • Masquerading as a default local account for the first time Medium (parent: Low)
  • Potential masquerading as a power user account Low
  • Masquerading as a default Administrator account Informational (parent: Low)