Adversaries may create a domain account to maintain access to victim systems. Domain accounts are those managed by Active Directory Domain Services where access and permissions are configured across systems and services that are part of that domain. Domain accounts can cover user, administrator, and service accounts. With a sufficient level of access, the net user /add /domain command can be used to create a domain account.(Citation: Savill 1999) Such accounts may be used to establish secondary credentialed access that do not require persistent remote access tools to be deployed on the system.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by T1136.002 Detection Strategy - Domain Account Creation Across Platforms
is blocked by Multi-factor Authentication
is blocked by Operating System Configuration
is blocked by Network Segmentation
is blocked by Privileged Account Management
is blocked by Access Restriction For Change
is blocked by Secure Baseline Configurations
is blocked by Least Functionality
is blocked by Continuous Monitoring
is blocked by Use of External Technology Assets, Applications and/or Services (TAAS)
is blocked by Endpoint File Integrity Monitoring (FIM)
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Authenticator Management
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Cross Domain Solution (CDS)
is blocked by Boundary Protection
is blocked by Data Flow Enforcement – Access Control Lists (ACLs)
Impressum German English