Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service. Local Accounts may also be abused to elevate privileges and harvest credentials through [OS Credential Dumping](https://attack.mitre.org/techniques/T1003). Password reuse may allow the abuse of local accounts across a set of machines on a network for the purposes of Privilege Escalation and Lateral Movement.

Linked Issues

Issuelinks
Linktype Issue
is related to Techniques
is blocked by Detection of Local Account Abuse for Initial Access and Persistence
is blocked by Privileged Account Management
is blocked by Multi-factor Authentication
is blocked by Password Policies
is blocked by User Account Management
is blocked by Access Restriction For Change
is blocked by Security, Compliance & Resilience Controls Oversight
is blocked by Secure Baseline Configurations
is blocked by Continuous Monitoring
is blocked by Encrypting Data At Rest
is blocked by Separation of Duties (SoD)
is blocked by Identification & Authentication for Organizational Users
is blocked by Account Management
is blocked by Access Enforcement
is blocked by Least Privilege
is blocked by Identity Proofing (Identity Verification)
is blocked by Secure Development Life Cycle (SDLC) Management
is blocked by Secure Engineering Principles
is blocked by Technology Development & Acquisition
is blocked by Developer Architecture & Design
is blocked by Secure Software Development Practices (SSDP)
is blocked by Security, Compliance & Resilience Testing Throughout Development
is blocked by Developer Configuration Management
is blocked by Developer-Provided Training
Impressum German English