T1078.003 — Local Accounts
T1078.003: Local Accounts
MITRE ATT&CK® Enterprise technique
| Tactics | Stealth, Persistence, Privilege Escalation, Initial Access |
| Platforms | Containers, ESXi, Linux, macOS, Network Devices, Windows |
| Permissions required | — |
| Version | 2.0 |
| Parent technique | T1078 |
Description
Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Local Accounts may also be abused to elevate privileges and harvest credentials through OS Credential Dumping. Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.
Detection
(no detection guidance published)
Data sources
- (none listed)
References
- ATT&CK page: https://attack.mitre.org/techniques/T1078/003
- ATT&CK Enterprise matrix: https://attack.mitre.org/matrices/enterprise/