Privileged local account creation
privileged_user_create
Creates a local user, adds it to the local administrators group, verifies the membership and then deletes it again. Account creation followed by a privileged group change is one of the highest-signal events an EDR can see.
What it needs before it will run
-
--i-understandNeeds explicit consent: this test changes machine state or fetches real offensive tooling.
Gates are cumulative and none of them is implied by another: see the three gates for why they are separate decisions.
ATT&CK techniques it exercises
| Technique | Name | Tactic | Across public reports |
|---|---|---|---|
| T1098 | Account Manipulation | Persistence | coverage statistics |
| T1136.001 | Create Local Account | Persistence | coverage statistics |
How often anything notices
Not enough data: fewer than 3 public reports have run this test, so no rate is published for it. Groups below that threshold are withheld everywhere on the site — with one or two contributors an average is one organisation's result with a percent sign after it.
Catalogue generated from client 0.1.0. A test's behaviour can
change between releases; this page describes the version named here.