MITRE ATT&CK · Enterprise

T1078.003 — Valid Accounts: Local Accounts

Sub-technique of T1078 Valid Accounts

ID
T1078.003
Platforms
Containers, ESXi, Linux, macOS, Network Devices, Windows
Tactics
Stealth Persistence Privilege Escalation Initial Access

Description

Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.

Detected by EasySIEM

This project's own SigmaHQ-derived detection pipeline tags every compiled rule with the ATT&CK technique(s) it maps to -- if a rule in your install covers this technique, its alerts show up automatically on your own EasySIEM Console's ATT&CK Reference page, no lookup needed. This page exists so a click from there always lands here on easysiem.com, not on attack.mitre.org.

View this technique on the official MITRE ATT&CK site ↗