Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Defense Evasion/ T1078.003

T1078.003Local Accounts

T1078.003 — Local Accounts is a MITRE ATT&CK technique in the Defense Evasion tactic. Clankerusecase tracks 7 detection use cases covering it and 2 threat-intel articles citing it.

Defense EvasionPersistencePrivilege EscalationInitial Access
View on the matrix → Filter Detection Library MITRE official spec ↗
7Use cases
2Articles
0Sub-techniques
4Tactics

Use cases covering this technique (7)

Cisco ASA - New Local User Account Created ESCU actions · hunting P Cisco ASA - User Privilege Level Change ESCU actions · hunting P Detect Excessive User Account Lockouts ESCU actions · hunting P Potential password in username ESCU actions · hunting P Short Lived Windows Accounts ESCU actions · alerting P [LLM] Rogue vSphere admin account creation via GoodMoodle-VCFleet UA from 146.59.252.178 Bespoke delivery · hunting DSΣPDDCS [LLM] Corporate sign-in from DPRK IT-worker VPS / AstrillVPN infrastructure (Famous Chollima) Bespoke delivery · hunting DSΣPDD

Articles citing this technique (2)