About this video
Detecting a breach is not always immediate, and sophisticated attackers may spend considerable time working to gain and maintain access before being noticed. To protect that access, they often establish persistence mechanisms that allow them to remain present on a network even after partial detection or remediation efforts. Creating unauthorized user accounts is one of the most straightforward methods for achieving this, as it gives an attacker a reliable pathway back into the environment without relying on the original vulnerability.
Unexpected accounts appearing on networked machines should be treated as a serious indicator of compromise. Security teams monitoring user account activity can catch this behavior early, making account auditing and alerting a valuable layer of a broader intrusion detection strategy. Any account that cannot be traced to a legitimate provisioning process warrants immediate investigation.
What you'll learn
- Identify the creation of unauthorized user accounts as a potential indicator of compromise and persistence mechanism used by threat actors.
What's covered
New Accounts as IoC
- Indicator of Compromise
- Unexpected new accounts
- Appears on network machines
- Attacker Behavior
- May take multiple attempts
- Caught and retries entry
- Establishing Persistence
- Goal after initial access
- Creating new accounts
Key terms
- Threat Actor
- An individual or group responsible for a security incident or attack.
- Persistence
- A MITRE ATT&CK tactic in which an adversary maintains their foothold within a compromised network to survive restarts, credential changes, or other interruptions.
- Indicators of Compromise
IoC
- Indicators of Compromise are forensic artifacts such as file hashes, IP addresses, domain names, and registry keys that provide evidence a system may have been compromised, enabling threat detection and intelligence sharing.
- Unauthorized User Account
- A user account created on a system or network without proper authorization, often used by threat actors to maintain persistent access.
Topics
Threat Detection
Indicators Of Compromise
Persistence Mechanisms
User Account Management
Unauthorized Access
Incident Response
Cybersecurity
About TechKnowSurge
TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.
Explore free tools and programs →