Analytics BIOC
Informational
✕
Suspicious domain user account creation
A user was observed creating a rare domain account.
- Module:
- Identity Analytics
- Data source:
- Windows Event Collector, XDR Agent with eXtended Threat Hunting (XTH)
ATT&CK tactics: Persistence (TA0003)
ATT&CK techniques: Create Account: Domain Account (T1136.002)
Attacker's goals:
Persistence using a valid account.
Investigative actions:
Check the user who created the account and verify its activity.
- Test period:
- N/A (single event)
- Deduplication:
- 1 Day