// MITRE ATT&CK

T1136.002 · Domain Account

🎯 Persistence LinuxmacOSWindows Sub-technique

Sub-technique of T1136 · Create Account.

Adversaries may create a domain account to maintain access to victim systems. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover user, administrator, and...

How to detect & mitigate it

Detecting Domain Account starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.