BIOC Informational

User account flagged as hidden

Look for unsigned processes that add an entry to the hidden users Registry key.

Module:
Platform Analytics
Agent event type:
Registry
Category:
Evasion
Status:
Enabled
ATT&CK tactics: Defense Evasion (TA0005)
ATT&CK techniques: Valid Accounts (T1078)
Indicator:

Registry action type = all AND registry data = 0 AND registry key name = *SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList Host host os = windows

Preventable: yes