Umbra Wiki technique technique/T1078.003
Back to wiki

T1078.003 — Local Accounts

provenance: imported · ATT&CK: T1078.003

T1078.003: Local Accounts

MITRE ATT&CK® Enterprise technique

Tactics Stealth, Persistence, Privilege Escalation, Initial Access
Platforms Containers, ESXi, Linux, macOS, Network Devices, Windows
Permissions required
Version 2.0
Parent technique T1078

Description

Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.

Detection

(no detection guidance published)

Data sources

  • (none listed)

References

  • ATT&CK page: https://attack.mitre.org/techniques/T1078/003
  • ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/