Detect New Local Admin Account

Description

This search looks for newly created accounts that have been elevated to local administrators.

Content Mapping

This content is not mapped to any local saved search. Add mapping


Use Case

Security Monitoring

Category

Malware

Alert Volume

This search looks for newly created accounts that have been elevated to local administrators.

SPL Difficulty

None

Journey

Stage 1

MITRE ATT&CK Tactics

Persistence

MITRE ATT&CK Techniques

Create Account

Local Account

MITRE Threat Groups

APT3
APT39
APT41
Dragonfly 2.0
Leafminer

Kill Chain Phases

Actions On Objectives
Command and Control

Data Sources

Windows Security

   Search

Open in Search