Suspicious Hidden Account Creation via Winlogon SpecialAccounts UserList Registry

PremiumReviewedSigma · High · v1
Product
windows
Category
registry_set
Author
HuntRule
Published
2026-09-12
Updated
2026-09-12

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects modification of the Winlogon SpecialAccounts UserList registry key to hide a local account from the Windows logon screen. The Chaos ransomware-as-a-service group sets a user value to 0 under this key to conceal accounts created for persistent access. Hiding accounts from the logon interface is a defense-evasion technique used to maintain covert access.

Related detections9 linkedT1564.002 — drag to rearrange
Hiding local user accounts
Malicious Hidden Local Account via Winlogon SpecialAccounts UserList
Suspicious Hidden Local Account via SpecialAccounts UserList Registry Value (via registry_set)
macOS dseditgroup Used to Add User to admin Group
macOS Root Account Enable Attempt via dsenableroot
macOS sysadminctl Used to Add User to Admin Group
macOS dscl Adds User to Admin Group via -append /Groups/admin GroupMembership
Windows Process Creation: Suspicious secedit.exe Security Policy Export or Configuration
Windows Registry: Hidden User via Winlogon SpecialAccounts Userlist Value 0
Suspicious Hidden Account Creation via Winlogon SpecialAccounts UserList Registry
Pivot detection · T1564.002 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.