Splunk Enterprise Security added a detection for Windows built-in account renaming, using Security Event ID 4781 to identify changes affecting reserved relative identifiers (RIDs) 500 through 504: Administrator, Guest, krbtgt, DefaultAccount, and WDAGUtilityAccount. The analytic is disabled by default and generates a notable event with a risk score of 50 when triggered.
Renaming the RID-500 Administrator account can let an intruder retain administrative privileges while evading detections that depend on the account’s default name. The behavior maps to MITRE ATT&CK T1036.010 (Masquerade Account Name) and T1078.003 (Valid Accounts: Local Accounts), techniques used to make malicious accounts appear legitimate and abuse local credentials for persistence, remote access, and lateral movement.

See real exploitation activity before you spend the cycle.
1 event from the most recent confirmed update back to the earliest known activity.
Splunk updated its "Windows Builtin Account Name Was Changed" Enterprise Security detection, which monitors Windows Security Event ID 4781 for renaming reserved built-in account SIDs with RIDs 500 through 504. The analytic is mapped to ATT&CK T1036.010 and T1078.003 and is disabled by default.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
4 references tracked. Mallory keeps watching after this page renders.
research.splunk.com
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceattack.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.