Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Persistence/ T1136.002

T1136.002Domain Account

T1136.002 — Domain Account is a MITRE ATT&CK technique in the Persistence tactic. Clankerusecase tracks 6 detection use cases covering it and 1 threat-intel article citing it.

Persistence
View on the matrix → Filter Detection Library MITRE official spec ↗
6Use cases
1Articles
0Sub-techniques
1Tactic

Use cases covering this technique (6)

Windows Computer Account Changed to Domain Controller ESCU actions · alerting P Windows ESX Admins Group Creation Security Event ESCU actions · alerting P Windows ESX Admins Group Creation via Net ESCU actions · alerting P Windows ESX Admins Group Creation via PowerShell ESCU actions · alerting P Windows Privileged Group Modification ESCU actions · alerting P [LLM] Certighost precursor: domain computer account created by low-privileged user (MAQ abuse) Bespoke install · hunting DSΣPDD

Articles citing this technique (1)