Analytics
Low
✕
Multiple suspicious user accounts were created
A user was observed creating multiple rare user accounts.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Create Account (T1136)
Attacker's goals:
Persistence using a valid account.
Investigative actions:
Check the user who created the accounts and verify the activity.
- Test period:
- 1 Hour
- Deduplication:
- 1 Day