Suspicious Local Administrator Account Addition via net localgroup

PremiumReviewedSigma · Medium · v1
Product
windows
Category
process_creation
Author
HuntRule
Published
2026-09-30
Updated
2026-09-30

ATT&CK techniques

Initial Access → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Execution

  4. Cred Access

  5. Discovery

  6. Lateral Movement

  7. Collection

  8. C2

  9. Exfiltration

  10. Impact

What it detects

This rule detects use of net or net1 to add an account to the local Administrators group, observed during a Huntress-tracked Bomgar exploitation campaign where attackers escalated privileges before ransomware deployment. Adding accounts to privileged groups from a command line is a common persistence and privilege-escalation technique. While administrators occasionally perform this manually, it should be corroborated with the initiating process context.

Related detections9 linkedT1136.001 — drag to rearrange
ScreenConnect Administrator Provisioning XML Written to Temp Directory (CWE-288)
Malicious Account Added to Domain Admins via net localgroup
Suspicious Local Account Creation and Privileged Group Addition via Net.EXE (via process_creation)
Linux: New user created with UID=0 or GID=0/10/27 indicating privileged group access
Cisco AAA local account and remote authentication changes
Suspicious Local Account Creation of DefaultService via Net User
Malicious Masquerading Local Account WDAGUtilltyAccount Created via net user
Suspicious Domain User Account Created via Net Command
Suspicious Local Account Creation Named DefaultService
Suspicious Local Administrator Account Addition via net localgroup
Pivot detection · T1136.001 · 9 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.