BIOC
Informational
✕
User account flagged as hidden
Look for unsigned processes that add an entry to the hidden users Registry key.
- Module:
- Platform Analytics
- Agent event type:
- Registry
- Category:
- Evasion
- Status:
- Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Valid Accounts (T1078)
Indicator:
Registry action type = all AND registry data = 0 AND registry key name = *SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList Host host os = windows
Preventable: yes