MITRE ATT&CK documents local account creation as a common persistence technique under T1136.001, describing how threat groups and malware have created or enabled accounts on compromised Windows systems to maintain access and support lateral movement. Reported activity includes use of built-in commands such as net user to add accounts, sometimes followed by placement into privileged groups, with examples ranging from generic support-style usernames to attacker-controlled administrator accounts.
Splunk published and later replaced a detection for this behavior that monitors endpoint process telemetry for net.exe or net1.exe creating local administrator accounts with the /add parameter and administrator-group keywords. The analytic, now superseded by Windows Create Local Administrator Account Via Net, is mapped to ATT&CK T1136.001 and is intended to help defenders spot suspicious account creation, while noting that legitimate IT administration can generate false positives.

Get the actors, campaigns, and ATT&CK mapping behind it.
2 events from the most recent confirmed update back to the earliest known activity.
Splunk removed the "Create local admin accounts using net exe" analytic from its Threat Research content library in version 5.2.0, stating it had been renamed and its logic updated. Splunk identified the replacement as "Windows Create Local Administrator Account Via Net."
Splunk published a detection analytic titled "Create local admin accounts using net exe" to identify attempts to create local administrator accounts via net.exe or net1.exe, mapped to MITRE ATT&CK T1136.001.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.