// MITRE ATT&CK

T1564.002 · Hidden Users

🎯 Stealth LinuxmacOSWindows Sub-technique

Sub-technique of T1564 · Hide Artifacts.

Adversaries may use hidden users to hide the presence of user accounts they create or modify. Administrators may want to hide users when there are many user accounts on a given system or if they want to hide their administrative or other management accounts from other users. In macOS, adversaries ...

How to detect & mitigate it

Detecting Hidden Users starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.