Skip to the content.

back

Find sigma rule :x:

Attack: Valid Accounts: Local Accounts

Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.

MITRE

Tactic

technique

Test : Add a new/existing user to the admin group using dseditgroup utility - macOS

OS

Description:

After execution the current/new user will be added to the Admin group

Executor

bash

Sigma Rule

back