Privileged local account creation

privileged_user_create

Creates a local user, adds it to the local administrators group, verifies the membership and then deletes it again. Account creation followed by a privileged group change is one of the highest-signal events an EDR can see.

Severity high how bad it would be if it were real
Expected outcome Something should notice
Platforms 3 macOS, Linux, Windows
Isolation subprocess runs in its own process, so a kill is a measurement

What it needs before it will run

  • --i-understand

    Needs explicit consent: this test changes machine state or fetches real offensive tooling.

Gates are cumulative and none of them is implied by another: see the three gates for why they are separate decisions.

ATT&CK techniques it exercises

MITRE ATT&CK techniques this test maps to.
Technique Name Tactic Across public reports
T1098 Account Manipulation Persistence coverage statistics
T1136.001 Create Local Account Persistence coverage statistics

How often anything notices

Not enough data: fewer than 3 public reports have run this test, so no rate is published for it. Groups below that threshold are withheld everywhere on the site — with one or two contributors an average is one organisation's result with a percent sign after it.

Catalogue generated from client 0.1.0. A test's behaviour can change between releases; this page describes the version named here.